logo

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

ID: 6e229e3f-6737-5e09-a78b-359fdefb22b4

STIX ID: report--6e229e3f-6737-5e09-a78b-359fdefb22b4

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-07-06

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**CVE-2026-20896 (CVSS 9.8)** in Gitea Docker images allowed unauthenticated attackers to impersonate any user via a trusted `X-WEBAUTH-USER` header because `REVERSE_PROXY_TRUSTED_PROXIES` was hard-coded to `*`; the issue was fixed in Gitea 1.26.3 but Sysdig observed initial exploitation attempts in the wild and about 6,200 internet-facing instances may be exposed, so immediate patching is advised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.