Alex Yao Alex Yao
Back to news
Cyber Security Published on July 10, 2026

Critical Gitea Docker authentication bypass CVE-2026-20896 actively exploited

CVE-2026-20896 affects official Gitea Docker images up to version 1.26.2.

The default configuration sets REVERSE_PROXY_TRUSTED_PROXIES=*.

An unauthenticated attacker can send an X-WEBAUTH-USER header to impersonate any user, including administrators.

Gitea released versions 1.26.3 and 1.26.4 to address the flaw; about 6,200 internet-facing instances are potentially exposed.