Groups
Groups
Sign in
Groups
Groups
Technical - Security - Patch Management
Conversations
About
Send feedback
Help
Urgent Action Required Gitea Docker Authentication Bypass (CVE-2026-20896 and CVE-2026-27771)
6 views
Skip to first unread message
Eyal Estrin
unread,
Jul 11, 2026, 4:09:05 AM (13 days ago)
Jul 11
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`
https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4
Emerging Threats: (CVE-2026-20896, CVE-2026-27771) Authentication Bypasses in Self-Hosted Gitea
https://www.cycognito.com/blog/emerging-threats-cve-2026-20896-cve-2026-27771-authentication-bypasses-in-self-hosted-gitea/
New CVE Detected (CVE-2026-20896)
https://www.ionix.io/threat-center/cve-2026-20896/
Gitea Docker image trusts spoofable reverse-proxy headers by default (CVE-2026-20896)
https://mondoo.com/vulnerability-intelligence/vulnerability/CVE-2026-20896
Gitea Docker image trusts spoofable reverse-proxy headers by default (CVE-2026-20896)
https://o3.security/vulnerability/CVE-2026-20896
Critical Vulnerability in Gitea Docker
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-083/
Critical Gitea vulnerability under active exploitation
https://secarma.com/08-07-2026-gitea-vulnerability-active-exploitation
Critical Gitea flaw allows authentication bypass via single HTTP header
https://www.scworld.com/brief/critical-gitea-flaw-allows-authentication-bypass-via-single-http-header
Eyal Estrin
Author | Cloud Architect | AWS • Azure • GCP Insights
Social: @eyalestrin
Connect
:
https://linktr.ee/eyalestrin
Blog
:
https://security-24-7.com
Reply all
Reply to author
Forward
0 new messages