Critical Gitea Docker auth bypass actively exploited
🔒 A critical authentication bypass (CVE-2026-20896) in the official Gitea Docker image is being actively exploited to impersonate any user, including administrators, when reverse-proxy authentication headers like X-WEBAUTH-USER are trusted from all sources. Sysdig reported the first in-the-wild exploitation roughly two weeks before public disclosure, and around 6,200 Gitea instances are internet-exposed. Gitea released versions 1.26.3 and 1.26.4 to address the issue and advises immediate upgrades or restricting REVERSE_PROXY_TRUSTED_PROXIES to known IPs.
