Gitea Docker image trusts spoofable reverse-proxy headers by default
Title source: cnaExploitation Summary
CVE-2026-20896 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 6 public exploits from researchers including Lite-os15, XaocZenon, HORKimhab.
AI-analyzed exploit summary The repository contains only a README.md file with a minimal title and no technical details, exploit code, or vulnerability analysis. It appears to be an incomplete or placeholder repository with no functional content.
Description
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
Exploits (6)
The repository contains only a README.md file with a minimal title and no technical details, exploit code, or vulnerability analysis. It appears to be an incomplete or placeholder repository with no functional content.
This repository contains a functional proof-of-concept exploit for CVE-2026-20896, an authentication bypass vulnerability in Gitea <=1.26.2. The exploit spoofs the X-WEBAUTH-USER header to impersonate users without credentials by abusing overly permissive reverse proxy trust settings (REVERSE_PROXY_TRUSTED_PROXIES=*).
The repository does not contain exploit code or technical analysis for CVE-2026-20896, an auth_bypass vulnerability in Gitea Docker images (≤1.26.2) due to misconfigured reverse-proxy trust settings. Instead, it links to external GitHub repos and an encrypted archive, lacking depth or proof-of-concept details.
This repository contains a functional proof-of-concept for CVE-2026-20896, an authentication bypass vulnerability in Gitea Docker images (≤1.26.2) where reverse-proxy authentication can be bypassed via the X-WEBAUTH-USER header. The PoC checks for vulnerable instances by sending crafted requests with the header and verifying impersonation via page title changes.
This repository provides a functional proof-of-concept exploit for CVE-2026-20896, a reverse-proxy authentication bypass in Gitea <=1.26.2 Docker images. The exploit spoofs the X-WEBAUTH-USER header to impersonate any user without authentication by abusing the default REVERSE_PROXY_TRUSTED_PROXIES=* configuration.
This repository contains a functional proof-of-concept exploit for CVE-2026-20896, an authentication bypass vulnerability in Gitea. The exploit leverages a directory traversal flaw in the API token validation logic to impersonate administrative users without valid credentials.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H