hacker-news · Crawled Jul 6, 2026

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

1 IoCs
Read original article ↗

AI Summary

Threat actors are actively probing and attempting to exploit CVE-2026-20896, a critical vulnerability in Gitea Docker images that allows unauthenticated remote users to gain elevated access by spoofing the 'X-WEBAUTH-USER' HTTP header. The flaw arises from the default configuration trusting all IP addresses due to a wildcard in the 'REVERSE_PROXY_TRUSTED_PROXIES' setting. Exploitation attempts were detected just 13 days after public disclosure, with initial activity observed from a ProtonVPN IP address. Although no full exploitation has been confirmed yet, the risk remains high for unpatched internet-facing instances.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
IP 159[.]26[.]98[.]241 Details →