Attackers are actively breaking into some internet-accessible Gitea code-hosting servers by abusing a critical authentication flaw. The bug, CVE-2026-20896, affects official Gitea Docker images before 1.26.3 when reverse-proxy authentication is enabled; an attacker can send a single crafted HTTP header with a valid username to bypass login. Sysdig says exploitation began 13 days after public disclosure, and roughly 6,200 Gitea instances are exposed online, though the vulnerable subset is unknown.
Why it matters: Organizations using self-hosted Gitea could have private source code, deploy keys, API keys, and other secrets exposed or modified without a password. This is urgent: admins should update to fixed Gitea versions immediately and ensure reverse-proxy authentication is not exposed directly to untrusted networks.
Ionut Arghire
2026.07.07
100% relevant
This article establishes a distinct tracked event by adding that CVE-2026-20896 in Gitea is under active exploitation in the wild, elevating the issue from a disclosed flaw to an urgent defender-relevant incident.
← Back to all stories