Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
https://www.securityweek.com/cisa-warns-of-exploited-gitea-vulnerability/
https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn/
https://latesthackingnews.com/2026/07/07/gitea-docker-vulnerability-exploitation/
https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html
https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.html
https://latesthackingnews.com/2026/07/15/uefi-secure-boot-bypass/
https://github.com/Lite-os15/Lab-001-Gitea-CVE-2026-20896-
https://github.com/shunfeng8421/exploit-library
https://github.com/shunfeng8421/security-audit
https://github.com/rz1027/CVE-2026-20896
https://github.com/sm-ard/devops-pulse
https://github.com/kaleth4/CVE-2026-20896
https://github.com/HORKimhab/poc-cve-collection
https://github.com/go-gitea/gitea/releases/tag/v1.26.3
Published: 2026-07-03
Updated: 2026-07-07
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.02755
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest