Exploited in the wild Gitea Docker Images web-app Gitea
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
CVE Tools coverage
Threat actors have been seen probing recently fixed Gitea Docker images for a critical authentication weakness tracked as CVE-2026-20896 (CVSS 9.8). The issue occurs when the Docker image default trusts all source IPs for the X-WEBAUTH-USER header, which can allow unauthenticated attackers to gain elevated access if reverse-proxy authentication is enabled and the allowlist is not restricted. This affects Gitea Docker image versions before and including 1.26.2, with the fix provided in version 1.26.3.