hacker-news · Crawled Jul 6, 2026
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
1 IoCs
Read original article ↗
AI Summary
Threat actors are actively probing and attempting to exploit CVE-2026-20896, a critical vulnerability in Gitea Docker images that allows unauthenticated remote users to gain elevated access by spoofing the 'X-WEBAUTH-USER' HTTP header. The flaw arises from the default configuration trusting all IP addresses due to a wildcard in the 'REVERSE_PROXY_TRUSTED_PROXIES' setting. Exploitation attempts were detected just 13 days after public disclosure, with initial activity observed from a ProtonVPN IP address. Although no full exploitation has been confirmed yet, the risk remains high for unpatched internet-facing instances.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 159[.]26[.]98[.]241 | Details → |