Known CVE
Gitea Docker Image <= 1.26.2 - Reverse Proxy Header Authentication Bypass
The official Gitea Docker image through version 1.26.2 ships with REVERSE_PROXY_TRUSTED_PROXIES set to a wildcard, causing Gitea to trust reverse-proxy authentication headers (X-WEBAUTH-USER) from any source IP instead of restricting trust to the configured reverse proxy. When reverse-proxy authentication is enabled, an unauthenticated remote attacker can impersonate any existing user, including an administrator, by sending the target username in the X-WEBAUTH-USER header.
CVE-2026-20896
Critical2026CVSS 9.8CWE-290
cve2026 · gitea · docker · auth-bypass · unauth · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website