CVE Tools

Critical Gitea Flaw Under Active Exploitation, Researchers Warn

SecurityWeekBy Ionut Arghire

Reported exploitedGitea

Our summary

Attackers are reportedly exploiting a vulnerability in Gitea’s reverse-proxy authentication logic to gain access to internet-reachable instances by providing only a valid username. The issue, affecting Gitea official Docker images before 1.26.3, is tracked as CVE-2026-20896 (CVSS 9.8) and can be triggered using a single HTTP header, enabling authentication bypass when reverse-proxy auth is configured incorrectly. Researchers say exploitation began shortly after disclosure, and organizations should upgrade to patched Gitea versions as quickly as possible to reduce risk of full compromise of repositories and secrets.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store