CVE-2026-20896Active Exploitation

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 22 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 41 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 93 mentions across 22 observed days

What's happening

  • Active exploitation reported across 41 signals
  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 17 signals
  • Patch or workaround mentioned in 31 signals
  • Technical details provided in 57 signals
  • General: 19 classified signals
  • Disclosure: 14 classified signals
  • Peaked 15d ago at 22 mentions (2026-07-06); latest day: 1
  • 93 total mentions across 22 days

Deep dive

Activity timeline93 mentions / 22d
06111722Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Mentions · 2026-06-30: 3Mentions · 2026-07-01: 1Mentions · 2026-07-04: 1Mentions · 2026-07-05: 2Mentions · 2026-07-06: 22Mentions · 2026-07-07: 17Mentions · 2026-07-08: 11Mentions · 2026-07-09: 5Mentions · 2026-07-10: 5Mentions · 2026-07-11: 5Mentions · 2026-07-12: 1Mentions · 2026-07-13: 3Mentions · 2026-07-15: 3Mentions · 2026-07-20: 1Mentions · 2026-07-23: 5Mentions · 2026-07-27: 1Mentions · 2026-07-30: 1Mentions · 2026-08-19: 1Mentions · 2026-08-26: 1Mentions · 2026-09-21: 1PoC Mentioned / Linked · 2026-06-26: 1PoC Mentioned / Linked · 2026-06-30: 3PoC Mentioned / Linked · 2026-07-01: 1PoC Mentioned / Linked · 2026-07-05: 1PoC Mentioned / Linked · 2026-07-07: 2PoC Mentioned / Linked · 2026-07-08: 3PoC Mentioned / Linked · 2026-07-09: 2PoC Mentioned / Linked · 2026-07-10: 3PoC Mentioned / Linked · 2026-07-20: 1Exploit Tool / Code · 2026-06-26: 1Exploit Tool / Code · 2026-06-30: 1Exploit Tool / Code · 2026-07-07: 1Exploit Tool / Code · 2026-07-08: 3Exploit Tool / Code · 2026-07-09: 2Exploit Tool / Code · 2026-07-10: 1Active Exploitation · 2026-07-06: 10Active Exploitation · 2026-07-07: 11Active Exploitation · 2026-07-08: 6Active Exploitation · 2026-07-09: 2Active Exploitation · 2026-07-10: 3Active Exploitation · 2026-07-11: 3Active Exploitation · 2026-07-20: 1Active Exploitation · 2026-07-23: 4Active Exploitation · 2026-08-26: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-07-04: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-06: 8Patch / Workaround · 2026-07-07: 6Patch / Workaround · 2026-07-08: 4Patch / Workaround · 2026-07-09: 3Patch / Workaround · 2026-07-10: 2Patch / Workaround · 2026-07-11: 1Patch / Workaround · 2026-07-12: 1Patch / Workaround · 2026-07-20: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 1Technical Details · 2026-07-04: 1Technical Details · 2026-07-05: 1Technical Details · 2026-07-06: 10Technical Details · 2026-07-07: 11Technical Details · 2026-07-08: 8Technical Details · 2026-07-09: 4Technical Details · 2026-07-10: 4Technical Details · 2026-07-11: 4Technical Details · 2026-07-12: 1Technical Details · 2026-07-13: 3Technical Details · 2026-07-15: 2Technical Details · 2026-07-20: 1Technical Details · 2026-07-27: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-26: 106-2506-3007-0407-0607-0807-1007-1207-1507-2307-3008-2609-21
Signal classification5 categories
Active Exploitation
4245.7%
General
1920.7%
Disclosure
1415.2%
PoC
1010.9%
Patch
77.6%
Referenced assets51 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-252
Disclosure1Patch1
2026-06-261
Disclosure1
2026-06-303
PoC3
2026-07-011
PoC1
2026-07-041
Patch1
2026-07-052
Disclosure1PoC1
2026-07-0622
Active Exploitation12Disclosure2General7Patch1
2026-07-0717
Active Exploitation10Disclosure1General5Patch1
2026-07-0811
Active Exploitation6General2Patch1PoC2
2026-07-095
Active Exploitation2General1Patch1PoC1
2026-07-105
Active Exploitation3PoC2
2026-07-115
Active Exploitation3General2
2026-07-121
Patch1
2026-07-133
Disclosure3
2026-07-153
Disclosure2General1
2026-07-201
Active Exploitation1
2026-07-235
Active Exploitation4General1
2026-07-271
Disclosure1
2026-07-301
Disclosure1
2026-08-191
Disclosure1
2026-08-261
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 CVE-2026-20896 saw its first in-the-wild attempt 13 days after disclosure. The Gitea Docker flaw lets reachable containers trust spoofed X-WEBAUTH-USER headers when reverse proxy auth is enabled. See which setups are exposed and where the probe stopped: https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html

    Post summary

    CVE‑2026‑20896 has been actively exploited in the wild, targeting Gitea Docker deployments that accept spoofed X‑WEBAUTH‑USER headers when reverse‑proxy authentication is enabled.

    1182741330.6K
    2.3M followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-20896 (CVSS 9.8): Gitea Docker images default REVERSE_PROXY_TRUSTED_PROXIES=* — with reverse-proxy auth on, any IP can impersonate any user via X-WEBAUTH-USER. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJHaXRlYSI= 🎯244.5K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Gitea" 🔖Refer: https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4 #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The tweet announces CVE-2026-20896 in Gitea Docker images, highlighting that default proxy settings allow user impersonation, and cites an advisory and numerous FOFA findings.

    417066178.8K
    14.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    🚨 Critical Gitea flaw CVE-2026-20896 is being probed in the wild Researchers warn that attackers are targeting a critical Gitea Docker image flaw that can allow authentication bypass with a single HTTP header. The issue affects official Gitea Docker images up to 1.26.2 when reverse-proxy authentication is enabled. The vulnerable default trusted any source IP as a reverse proxy, meaning an attacker who could reach the container’s HTTP port could spoof X-WEBAUTH-USER and impersonate a known or guessable user. Gitea patched the issue in 1.26.3 / 1.26.4, and a public PoC/checker is now available. Sysdig says the first in-the-wild probing was seen 13 days after disclosure. Observed IP: 159[.]26[.]98[.]241

    Post summary

    CVE-2026-20896 is an authentication bypass flaw in Gitea Docker images that is actively exploited in the wild, with probing observed 13 days post‑disclosure, and has been patched in newer releases.

    290451614.6K
    234.6K followersView on X
  • Dark Web Informer@DarkWebInformer
    PoC

    CVE-2026-20896: Gitea Docker Auth Bypass Checker GitHub: https://github.com/szybnev/cve-2026-20896-gitea-poc

    Post summary

    A GitHub repository provides a Proof of Concept for CVE‑2026‑20896, presenting a tool that checks for Docker authentication bypass in Gitea.

    1100341511.2K
    234.6K followersView on X
  • Nicolas Krassas@Dinosn
    Active Exploitation

    Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html

    Post summary

    Threat actors are probing the Gitea Docker flaw 13 days after disclosure, indicating potential active exploitation but no further technical details are provided.

    1401332.8K
    160.8K followersView on X
  • siri@fu4k1@sirifu4k1
    PoC

    CVE-2026-20896:Gitea Docker Auth Bypass Checker curl -s -L -H "X-WEBAUTH-USER: <username>" http://localhost:3000/ | grep -oE '<title>[^<]+</title>' https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4

    Post summary

    Demonstrates a curl‑based proof of concept for CVE‑2026‑20896 that bypasses authentication in a Gitea Docker container, with no mention of active exploitation or a patch.

    120951.6K
    7.1K followersView on X
  • Azubuike Ibe@ai_dev_official
    Disclosure

    CVE-2026-20896 is a CVSS 9.8. In the Gitea Docker image. And it has been out for less than two weeks. The flaw is in the default configuration. When reverse-proxy authentication is enabled, REVERSE_PROXY_TRUSTED_PROXIES defaults to wildcard. An attacker can spoof the X-WEBAUTH-USER header and bypass authentication entirely. No credentials needed. What sits behind that authentication bypass on a typical Gitea deployment: repositories, CI/CD secrets, SSH keys, admin access. Everything. Patched versions are 1.26.3 and 1.26.4. If you have not updated, your instance is exposed. Here is what makes this class of vulnerability dangerous. Self-hosted tools get treated differently. Teams that would never delay a cloud service patch will let an internal Gitea or Forgejo instance sit unpatched for months. The thinking is that it is internal, so it is safer. It is not safer. It is just less visible. To you. Not to scanners. With a 9.8 CVSS and a straightforward header-spoofing exploit, internet-exposed instances of this will get scanned. That is not speculation. That is how the economics of exploitation work in 2026. Self-hosted DevOps infrastructure is part of your attack surface. It needs the same patching cadence, the same monitoring, and the same assume-breach posture as anything facing the internet directly. Internal does not mean safe. It means you are the only one watching. My name is Azubuike Ibe and I write about the vulnerabilities that get ignored because they live on the inside. Share this with any team running self-hosted Git infrastructure. They need to see it. #Cybersecurity #Gitea #Docker #DevOpsSecurity #DevSecOps

    Post summary

    The post announces CVE-2026-20896, outlining an authentication bypass in Gitea’s default config and urging users to apply the listed patches.

    01075209
    1.5K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Discover critical Gitea security flaws exposing servers to account takeovers and SSRF attacks. Read about CVE-2026-20896 and CVE-2026-22874 patches today. #Gitea #Cybersecurity #CVE202620896 #CVE202622874 #Vulnerability https://securityonline.info/critical-gitea-security-flaws https://t.co/FB9mdQykMY

    Post summary

    The tweet announces critical Gitea vulnerabilities enabling account takeover and SSRF attacks, and informs that patches are now available.

    04070616
    12.8K followersView on X
  • Poxek AI@szybnev
    General

    1/ CVE-2026-20896 is a critical Gitea Docker auth bypass. If reverse-proxy auth is enabled and the container HTTP port is reachable directly, a single header can impersonate a known user: X-WEBAUTH-USER: admin https://t.co/HEUtJGJwwh

    Post summary

    The tweet announces CVE‑2026‑20896 as a critical Gitea Docker authentication bypass that allows user impersonation via the X‑WEB‑AUTH‑USER header when reverse‑proxy authentication is enabled and the container’s HTTP port is exposed.

    80000103
    13 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Active Exploitation

    Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html?m=1

    Post summary

    The article reports that threat actors are actively probing the recently disclosed Gitea Docker flaw (CVE-2026-20896) more than ten days after its disclosure, with no PoC, patch, or false‑positive discussion provided.

    10041617
    18.1K followersView on X
  • Alice Sn0w •ᴗ•@Sn0wAlice
    PoC

    L'exploit le plus sympa de la semaine revient à: https://vuln.mlab.sh/cve/CVE-2026-20896 https://t.co/74dOTsWRQ6

    Post summary

    The tweet shares a link to CVE-2026-20896, implying a PoC exists but provides no explicit code, active exploitation details, patches, or technical depth.

    01040602
    1.6K followersView on X
  • いけむらさん@fd0
    PoC

    匿名の研究者がゼロデイ数件をGitHubリポジトリで公開(CVE-2026-55200、CVE-2026-20896) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/46394/

    Post summary

    An anonymous researcher disclosed PoC code for two zero-day vulnerabilities, CVE-2026-55200 and CVE-2026-20896, on a GitHub repository

    00032561
    2.1K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-20896 PT ID: PT-2026-52216 Vendor: Gitea Product: Gitea Open Source Git Server Description: Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-52216 • https://github.com/rz1027/CVE-2026-20896 #dbugs_vuln

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑20896 has been published, detailing how the Gitea Docker image allows IP impersonation via a misconfigured proxy setting.

    01021855
    3.4K followersView on X
  • cyber_updates_365@CyberUpdates365
    Patch

    ⚠️ DevOps & Sysadmins: Running self-hosted Gitea in Docker? CVE-2026-20896 allows full admin takeover via the X-WEBAUTH-USER header due to a proxy bug! 🛡️💻 Mitigation steps 👇 https://cyberupdates365.com/cve-2026-20896-gitea-docker-auth-bypass-fix/ #DevSecOps #Docker

    Post summary

    The post highlights a new Gitea Docker CVE that allows full admin takeover via the X-WEBAUTH-USER header and shares mitigation steps, indicating remediation is available.

    0004066
    13 followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    Hackers are actively exploiting a critical auth bypass in Gitea's official Docker image, tracked as CVE-2026-20896. Default config trusts the X-WEBAUTH-USER header from any IP, letting attackers impersonate any user, including admins, with no password needed. About 6,200 instances are exposed publicly. Patched in Gitea 1.26.3/1.26.4.

    Post summary

    CVE‑2026‑20896 is currently being exploited in the wild through an auth bypass in Gitea's Docker image, with the vulnerability mitigated in recent releases.

    00021523
    601 followersView on X
  • ET Labs@ET_Labs
    General

    13 new OPEN, 23 new PRO (13 + 10) Gitea API Authentication Bypass (CVE-2026-20896), OPNsense Secrets Disclosure via XPATH Injection (CVE-2026-53582), Microsoft SharePoint Taxonomy SQLi (CVE-2026-26114), and more https://community.emergingthreats.net/t/ruleset-update-summary-2026-07-09-v11230/3379

    Post summary

    The post lists new CVEs with brief vulnerability type descriptions, but provides no details on PoC, exploit code, active exploitation, or remediation.

    02010334
    5.7K followersView on X
  • Justin Kwon@ju571nK
    Active Exploitation

    Gitea の Docker イメージに CVE-2026-20896(CVSS 9.8)。デフォルト設定のせいで、X-WEBAUTH-USER ヘッダを送るだけで誰でも管理者になれてしまう問題。Sysdig が実際の悪用の試みを検知したとのこと。1.26.3 で直っているので、self-host してる人は早めに更新した方がいい。 #セキュリティ #DevSecOps #Gitea https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html

    Post summary

    CVE‑2026‑20896 permits privilege escalation in Gitea Docker images through the X‑WEBAUTH‑USER header; Sysdig detected active exploitation attempts, and the flaw is fixed in version 1.26.3, which users should update immediately.

    2001069
    6 followersView on X
  • rz1027@the_rz1027

    A throwback to the crazy critical I found on Gitea CVE-2026-20896 https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4 https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html

    00011120
    40 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-20896 (CVSS 9.8) in Gitea Docker images before 1.26.3 is actively exploited: a single X-WEBAUTH-USER header impersonates any user, including admins. Update to 1.26.3+ and audit exposed repos for stolen API keys and deploy tokens. #DFIR_Radar https://t.co/r4eEiBWji4

    Post summary

    CVE-2026-20896 allows attackers to impersonate any Gitea user via the X-WEBAUTH-USER header and is actively exploited; update to version 1.26.3+ and audit exposed repositories for API keys and deploy tokens.

    10010231
    1.7K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical improper access control in #Gitea. CVE-2026-20896 CVSS: 9.8. This flaw allows an attacker to impersonate any user via crafted reverse-proxy headers! #Patch #Patch #Patch More info: https://blog.gitea.com/release-of-1.26.3-and-1.26.4/

    Post summary

    The message alerts about a critical improper access control flaw (CVE-2026-20896) in Gitea that allows user impersonation via crafted reverse‑proxy headers, and announces that a patch is available.

    02000371
    7.2K followersView on X

Explore more