Researchers warn Gitea CVE-2026-20896 is now being actively exploited (thecybersecguru.com)
from UnLocoPoco@lemmy.world to cybersecurity@infosec.pub on 08 Jul 08:15
https://lemmy.world/post/49177672

Researchers are warning that CVE-2026-20896, a critical authentication bypass affecting Gitea Docker deployments using reverse-proxy authentication, is now seeing active exploitation. Under specific misconfigurations, attackers can spoof the X-WEBAUTH-USER header to impersonate arbitrary users, potentially leading to full repository compromise. The issue has been fixed in Gitea 1.26.4 (and corresponding patched releases for supported branches), so administrators should update as soon as possible. If you’re using reverse-proxy authentication, it’s also worth reviewing your proxy configuration to ensure authentication headers cannot be supplied by untrusted clients.

#cybersecurity

threaded - newest