Critical Gitea Security Flaws Expose Servers to Takeover
PoC publicGiteaOur summary
A pair of critical security issues in Gitea could allow remote attackers to bypass authentication and perform Server-Side Request Forgery (SSRF) attacks, potentially leading to full takeover of administrative accounts. The affected vulnerabilities are tracked as CVE-2026-20896 (critical, impacts Gitea Docker deployments using reverse proxy authentication due to overly trusting proxy headers) and CVE-2026-22874 (high, allows incomplete SSRF filtering in webhook and repository migration paths). Both issues affect Gitea versions 1.26.2 and earlier, so administrators should upgrade to Gitea version 1.26.3 immediately.
Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.