CVE Tools

Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure

The Hacker NewsBy The Hacker News

Reported exploitedGitea Docker Images

Our summary

Threat actors have been seen probing recently fixed Gitea Docker images for a critical authentication weakness tracked as CVE-2026-20896 (CVSS 9.8). The issue occurs when the Docker image default trusts all source IPs for the X-WEBAUTH-USER header, which can allow unauthenticated attackers to gain elevated access if reverse-proxy authentication is enabled and the allowlist is not restricted. This affects Gitea Docker image versions before and including 1.26.2, with the fix provided in version 1.26.3.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store