Skip to content

Known CVE

Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication Bypass

The official Gitea Docker image through version 1.26.2 ships with REVERSE_PROXY_TRUSTED_PROXIES set to a wildcard, causing Gitea to trust reverse-proxy authentication headers (X-WEBAUTH-USER) from any source IP instead of restricting trust to the configured reverse proxy. When reverse-proxy authentication is enabled, an unauthenticated remote attacker can impersonate any existing user, including an administrator, by sending the target username in the X-WEBAUTH-USER header.

CVE-2026-20896

Critical2026CVSS 9.8CWE-290

cve2026 · gitea · docker · auth-bypass · unauth · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website