FILTERING BY: CLEAR FILTER

Critical Authentication Bypass in Gitea CVE-2026-20896

CVE-2026-20896 is a critical authentication bypass vulnerability (CVSS 9.8) affecting Gitea official Docker images prior to version 1.26.3. The flaw stems from a logic error where the application improperly trusts the X-WEBAUTH-USER HTTP header regardless of the source IP address. By injecting this header, an unauthenticated remote attacker can impersonate any user, including administrators, gaining full unauthorized access to the instance. This vulnerability is under active exploitation, with attackers targeting CI/CD environments to exfiltrate sensitive source code, API tokens, and SSH keys. Immediate patching to version 1.26.3 and configuration of upstream proxy header stripping are required.


LINK COPIED TO CLIPBOARD