logo

Hackers exploit critical auth bypass in Gitea Docker image

ID: b33a8447-f461-5e20-be80-43201cc41b47

STIX ID: report--b33a8447-f461-5e20-be80-43201cc41b47

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-07-10

Date Updated: 2026-07-19

Author: Bill Toulas

...
...

A critical authentication-bypass vulnerability (CVE-2026-20896) in Gitea's official Docker image—caused by the default REVERSE_PROXY_TRUSTED_PROXIES='*' configuration trusting X-WEBAUTH-USER headers from any client—allows unauthenticated attackers to impersonate arbitrary users (including admins). Exploitation was observed in the wild shortly before disclosure, around 6,200 Gitea instances are publicly reachable, and Gitea has released patched versions (1.26.3/1.26.4) with guidance to upgrade or restrict trusted proxy IPs as mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.