CVE-2026-20896, a critical 9.8 CVSS vulnerability in the official Gitea Docker image, is now under active exploitation just 13 days after a patch was released. The flaw stems from the Docker image's default app.ini setting REVERSE_PROXY_TRUSTED_PROXIES being set to a wildcard, allowing any attacker who can reach the container's HTTP port to impersonate any user, including admins, by forging a single X-WEBAUTH-USER header. Sysdig researchers detected the first in-the-wild probing attempt originating from a ProtonVPN exit node. With roughly 6,200 internet-facing Gitea instances indexed on Shodan, the risk is significant given that Gitea typically stores source code, CI configs, API keys, and deployment credentials. Gitea versions 1.26.3 and 1.26.4 fix this bug along with nine other issues including SSRF, branch-permission escalation, TOTP replay, and an OAuth2 reactivation flaw. Admins should update immediately, restrict REVERSE_PROXY_TRUSTED_PROXIES to the actual proxy address, and audit admin session logs.

4m read timeFrom latesthackingnews.com
Post cover image
Table of contents
What the Gitea Docker vulnerability breaksSysdig catches attackers probing the doorWhy an exposed Gitea instance mattersWhat to fix, and what else shipped alongside it
347 Impressions