CVE Tools

Critical Gitea Security Flaws Expose Servers to Takeover

Daily CyberSecurity (securityonline.info)

PoC publicGitea

Our summary

A pair of critical security issues in Gitea could allow remote attackers to bypass authentication and perform Server-Side Request Forgery (SSRF) attacks, potentially leading to full takeover of administrative accounts. The affected vulnerabilities are tracked as CVE-2026-20896 (critical, impacts Gitea Docker deployments using reverse proxy authentication due to overly trusting proxy headers) and CVE-2026-22874 (high, allows incomplete SSRF filtering in webhook and repository migration paths). Both issues affect Gitea versions 1.26.2 and earlier, so administrators should upgrade to Gitea version 1.26.3 immediately.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store