Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-20896
CVE
CVE-2026-20896
View on NVD ↗
Gitea Docker image trusts spoofable reverse-proxy headers by default
MITRE ATT&CK TTPs
1
T1078.002
Domain Accounts
Defense Evasion
Source Articles
Hackers exploit critical auth bypass in Gitea Docker image
Hackers are actively exploiting a critical authentication bypass vulnerability, CVE-2026-20896, in the official Gitea Docker image. The flaw allows unauthenticated attackers to impersonate any user, including administrators, by spoofing the X-WEBAUTH-USER header when reverse proxy settings are misconfigured. The vulnerability affects Gitea Docker images up to version 1.26.2 in default configurations, and exploitation has already been observed in the wild. Singapore’s Cybersecurity Agency (CSA) has issued a warning, urging users to upgrade to patched versions 1.26.3 or 1.26.4.
bleeping-computer
Jul 10, 2026