gitea News Articles

Recent news articles refferecing the vendors vulnerabilities.

Gitea Docker Flaw Now Actively Probed: One Header Grants Admin Access to Source Code

Gitea Docker CVE-2026-20896 is under active scanning: Sysdig detected attackers probing the CVSS 9.8 authentication bypass 13 days after the advisory, using one HTTP header to claim admin access to

Hackers exploit critical auth bypass in Gitea Docker image

Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators.

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Ravie LakshmananJul 06, 2026Vulnerability / DevOps

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

Threat actors are exploiting a vulnerability in Gitea’s reverse-proxy authentication mechanism to access internet-accessible instances by supplying only a valid username.

Gitea Docker Images Ship Critical Authentication Bypass by Default

Threat actors began probing CVE-2026-20896 in Gitea Docker images just 13 days after disclosure. The critical authentication bypass stems from a permissive default configuration that lets attackers impersonate users via a spoofed HTTP header. With thousands of instances exposed, organizations must u...

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

CVE-2026-20896 lets reachable Gitea Docker containers trust spoofed X-WEBAUTH-USER headers when reverse proxy auth is enabled.

Gitea Container Vulnerability Exposes Private Container Images to Attackers - IT Security News

A critical security vulnerability in Gitea’s built-in container registry exposes private container images to unauthenticated attackers, raising significant concerns for organizations that rely on self-hosted Git and CI/CD environments. The flaw, tracked as CVE-2026-27771, allows remote attackers to ...

Gitea Container Registry Vulnerability Could Lead to Private Image Exposure - IT Security News

A critical vulnerability, tracked as CVE-2026-27771, has been discovered in Gitea’s built-in container registry, allowing unauthenticated remote attackers to access private container images without credentials. This flaw poses a serious risk as it can expose sensitive application data, including sou...

Gitea Flaw Left 30,000 Deployments' Private Container Images Readable for 4 Years

Gitea vulnerability CVE-2026-27771 let anyone pull private container images from 30,000-plus self-hosted deployments with no credentials required. Noscope found the flaw affected healthcare,

Gitea Vulnerability Exposed 30,000 Deployments to Attacks

CVE-2026-27771, an access control vulnerability in Gitea, exposed over 30,000 deployments to unauthorized access.

Gitea Vulnerability Exposes Private Container Images without Authentication

Gitea flaw CVE-2026-27771 exposed private container images across 30,000 deployments, risking unauthorized access worldwide.

No more news articles to load.