
🚨 Three Gitea/Gogs vulnerabilities just dropped — and one is a CVSS 9.8 authentication bypass. If you self-host Gitea or Gogs, this is not a “patch later” situation: ⚠️ CVE-2026-20896 — Gitea Docker auth bypass Anyone can impersonate any user with one HTTP header: X-WEBAUTH-USER: admin ⚠️ CVE-2026-52807 — Stored DOM XSS A malicious milestone name can survive escaping and execute through Semantic UI. ⚠️ CVE-2026-22874 — Webhook SSRF Gitea webhooks can become a path to AWS IMDS, cloud credentials, S3, Secrets Manager, ECR, and full cloud privilege abuse. Self-hosted Git platforms hold source code, CI/CD secrets, deploy keys, webhooks, tokens, and internal infrastructure access. Your code. Your secrets. Their access. Upgrade now: Gitea 1.26.3+ Gogs 0.14.3+ Full technical breakdown 👇 https://thecybersecguru.com/news/cve-2026-20896-gitea-authentication-bypass-dom-xss-ssrf/ #Gitea #Gogs
Post summary
The tweet announces three newly discovered Gitea/Gogs vulnerabilities, provides detailed technical information for each, links to a deeper breakdown, and urges users to apply specific patch versions.

