Reverse Proxy Vulnerability in Gitea Docker Image Affects User Authentication
CVE-2026-20896

9.8CRITICAL

Key Information:

Vendor

Gitea

Vendor
CVE Published:
3 July 2026

Badges

📈 Trended📈 Score: 3,180💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 31%📰 News Worthy

What is CVE-2026-20896?

CVE-2026-20896 is a critical vulnerability found in the Gitea Docker image, specifically in versions up to and including 1.26.2. Gitea is a lightweight self-hosted Git service that is widely used for version control and collaborative coding projects. This vulnerability arises from the default configuration of the REVERSE_PROXY_TRUSTED_PROXIES setting, which is set to allow any source IP address to impersonate a user. When the reverse-proxy authentication headers, like X-WEBAUTH-USER, are enabled, attackers can exploit this flaw to bypass user authentication processes and gain unauthorized access to user accounts. This poses a significant threat to organizations utilizing Gitea for their software development and management needs, potentially leading to data breaches, unauthorized actions, and escalating security risks.

Potential Impact of CVE-2026-20896

  1. Unauthorized Access: Attackers can impersonate legitimate users, allowing them to gain unauthorized access to sensitive data and functionalities within Gitea. This can lead to significant data breaches and compromise of user confidentiality.

  2. Impersonation Risks: The ability to impersonate users can enable malicious actors to perform actions under the guise of legitimate users, which could include modifying repositories, deleting critical data, or deploying unauthorized changes to projects.

  3. Widespread Exposure: Given the ease of exploitation due to default settings, organizations may face widespread security exposure, increasing the risk of being targeted by cybercriminals, including organized ransomware groups, which could lead to damaging repercussions for affected entities.

Affected Version(s)

Gitea Open Source Git Server 0 <= 1.26.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Gitea Docker Flaw Now Actively Probed: One Header Grants Admin Access to Source Code

Gitea Docker CVE-2026-20896 is under active scanning: Sysdig detected attackers probing the CVSS 9.8 authentication bypass 13 days after the advisory, using one HTTP header to claim admin access to

2 weeks ago

Hackers exploit critical auth bypass in Gitea Docker image

Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows attackers to impersonate any user, including administrators.

2 weeks ago

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

Ravie LakshmananJul 06, 2026Vulnerability / DevOps

3 weeks ago

References

EPSS Score

31% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 📈

    Vulnerability started trending

  • 💰

    Used in Ransomware

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

rz1027
.