---
schema: 1
kind: vulnerability
title: >
  CVE-2026-20896 — Gitea (Docker): trust-all reverse-proxy default lets an unauthenticated
  attacker impersonate any user via X-WEBAUTH-USER
headline: >
  CVE-2026-20896 — Gitea (Docker): trust-all reverse-proxy default lets an unauthenticated
  attacker impersonate any user via X-WEBAUTH-USER
summary: >
  *Gitea's Docker image shipped with REVERSE_PROXY_TRUSTED_PROXIES defaulting to the trust-all
  wildcard , so anyone who can reach the container's HTTP port can forge an X-WEBAUTH-USER header
  and authenticate as any account — including admin — with no credentials (CVE-2026-20896, CVSS
  9.8).** BSI flagged it as "hoch" on 2026-06-22; Gitea is the self-hosted Git platform of choice
  for DACH/EU sovereign-cloud and public-sector DevOps. Patched in 1.26.3 / 1.26.4 (Gitea,
  2026-06-21).
discovered_at: "2026-06-23T04:52:46Z"
updated_at: "2026-07-10T12:53:00Z"
event_date: 2026-06-22
run_id: 2026-06-23-165387f6
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - pre-auth
  - default-config
  - patch-available
  - actively-exploited
  - poc-public
regions:
  - europe
  - dach
  - global
  - switzerland
sectors:
  - public-sector
  - technology
  - education
entities: []
techniques:
  - T1190
affected_products:
  - Gitea
cves:
  - id: CVE-2026-20896
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - poc-public
      - patch-available
    affected: Gitea official Docker image ≤ 1.26.2
    fixed: 1.26.3 (1.26.4 recommended)
sources:
  - url: "https://blog.gitea.com/release-of-1.26.3-and-1.26.4"
    publisher: Gitea release notes
    role: primary
  - url: "https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4"
    publisher: GitHub Security Advisory GHSA-f75j-4cw6-rmx4
    role: corroborating
  - url: "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2027"
    publisher: BSI WID-SEC-2026-2027
    role: corroborating
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12755"
    publisher: NCSC-CH Cyber Security Hub
    date: 2026-07-10
    role: primary
  - url: "https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn"
    publisher: SecurityWeek
    date: 2026-07-07
    role: corroborating
  - url: "https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html"
    publisher: The Hacker News (citing Sysdig)
    date: 2026-07-06
    role: corroborating
closed_sources: []
evidence:
  - quote: "the Docker image defaulted REVERSE_PROXY_TRUSTED_PROXIES to wildcard '*' ... anyone who can reach the container's HTTP port can authenticate as any Gitea user by supplying an X-WEBAUTH-USER header"
    publisher: GitHub Security Advisory GHSA-f75j-4cw6-rmx4
  - quote: "WID-SEC-2026-2027 — Gitea: Mehrere Schwachstellen ermöglichen nicht autorisierten Zugriff und weitere Angriffe — Risiko: hoch"
    publisher: BSI WID
  - quote: "Current exploitation status: Actively Exploited, Proof of Concept Available"
    publisher: NCSC-CH Cyber Security Hub
  - quote: Successful exploitation allows unauthenticated attackers to gain full administrative control of Gitea instances via a single custom HTTP header.
    publisher: NCSC-CH Cyber Security Hub
  - quote: "So far, the activities have been related to initial investigation by the threat actor,"
    publisher: The Hacker News (citing Sysdig)
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Patch self-hosted Gitea to 1.26.4 and fix the reverse-proxy trust scope now** if you run the Docker image — set `REVERSE_PROXY_TRUSTED_PROXIES` to your exact proxy IP/CIDR, or disable `ENABLE_REVERSE_PROXY_AUTHENTICATION` if you don't use header-auth. CVE-2026-20896 is an unauthenticated admin-takeover (CVSS 9.8)."
  - "Treat internet-reachable Gitea Docker instances as urgent: upgrade to ≥ 1.26.4 now, and set REVERSE_PROXY_TRUSTED_PROXIES to the exact proxy IP/CIDR (never the wildcard) or disable ENABLE_REVERSE_PROXY_AUTHENTICATION if header-auth is unused."
  - "Hunt Gitea sign-in/audit logs for X-WEBAUTH-USER-authenticated admin sessions whose source IP is not the configured trusted proxy — by construction any such hit is a spoofed header, and it is the discriminator that separates exploitation from legitimate proxy auth."
updates:
  - at: "2026-07-10T12:53:00Z"
    run_id: 2026-07-10T1228Z-intel
    type: update
    summary: >
      Switzerland's NCSC published an advisory on 2026-07-10 raising the exploitation status of the
      Gitea Docker-image reverse-proxy auth bypass (CVE-2026-20896, CVSS 9.8) to "Actively Exploited,
      Proof of Concept Available". The underlying flaw — the official Docker image trusting a
      spoofable X-WEBAUTH-USER header from any source IP for unauthenticated admin impersonation — was
      covered on 2026-06-23; the in-window delta is the national-CERT exploitation-status escalation.
      Public telemetry to date (Sysdig, via SecurityWeek/The Hacker News) still shows only
      reconnaissance-stage probing, so treat NCSC-CH's "actively exploited" label as a
      national-authority assessment and prioritise patching internet-reachable Docker instances now.
    fields:
      - actions
      - affected_products
      - cves
      - evidence
      - regions
      - sources
      - tags
      - techniques
      - body
    merged_from: 2026-07-10/gitea-cve-2026-20896-ncsc-ch-actively-exploited-update
migrated_from: briefs/2026-06-23.md
---

Gitea 1.26.3 (2026-06-20) and 1.26.4 (2026-06-21) fix a cluster of four flaws; the critical one is **CVE-2026-20896 (CVSS 9.8)**. The official Gitea Docker image shipped with `REVERSE_PROXY_TRUSTED_PROXIES` defaulting to the wildcard `*`, meaning Gitea trusts the reverse-proxy authentication header from *any* source. Any attacker who can reach the container's HTTP port can therefore send an `X-WEBAUTH-USER` header naming an arbitrary user — including an administrator — and be authenticated as that user with no credentials ([Gitea, 2026-06-21](https://blog.gitea.com/release-of-1.26.3-and-1.26.4); [GitHub Security Advisory GHSA-f75j-4cw6-rmx4, 2026-06-21](https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4)). Bare-metal deployments with an explicit trusted-proxy CIDR are unaffected unless they also set the wildcard. The same release also patches CVE-2026-27775 (protected-branch enforcement race in single-push batch operations), CVE-2026-20779 (CVSS 7.1 — TOTP 2FA bypass via a web-flow TOCTOU race and stateless `X-Gitea-OTP` replay inside the OTP validity window) and CVE-2026-22874 (SSRF in the webhook / repo-migration subsystems). Germany's BSI issued WID-SEC-2026-2027 on 2026-06-22 rating the set "hoch" ([BSI WID, 2026-06-22](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2027)). No in-the-wild exploitation reported yet; included on the pre-auth-critical-on-widely-deployed-software gate. Gitea is the dominant self-hosted GitHub alternative across DACH/EU public-sector DevOps and sovereign-cloud environments, so an internet-reachable or loosely-segmented Docker instance is an immediate admin-takeover risk (`T1190` Exploit Public-Facing Application, `T1078.001` Default Accounts). Mitigations: set `REVERSE_PROXY_TRUSTED_PROXIES` to the exact reverse-proxy IP/CIDR, or disable `ENABLE_REVERSE_PROXY_AUTHENTICATION` entirely if header-auth is not used; upgrade to 1.26.4. Hunt for admin logins sourced from the reverse-proxy IP with no corresponding password-auth audit entry, and webhook calls to RFC-1918 addresses.

## Update — 2026-07-10T12:53:00Z

Switzerland's NCSC added CVE-2026-20896 to its Cyber Security Hub on 2026-07-10 (08:55 UTC) and set its current exploitation status to "Actively Exploited, Proof of Concept Available", reiterating that "[s]uccessful exploitation allows unauthenticated attackers to gain full administrative control of Gitea instances via a single custom HTTP header" ([NCSC-CH, 2026-07-10](https://security-hub.ncsc.admin.ch/#/posts/12755)). This is the first national-CERT escalation of the flaw's status since the June disclosure of the Docker image's trust-all `REVERSE_PROXY_TRUSTED_PROXIES` default (mechanics and patch unchanged from the original entry).

The escalation warrants a caveat rather than a panic. The only public exploitation reporting traces to Sysdig telemetry surfaced on 2026-07-06, and the two outlets that carried it diverge. The Hacker News quotes Sysdig's Michael Clark saying the single probe from a ProtonVPN-associated IP had "not so far progressed to any exploitation or attack progress" and characterises the activity as initial investigation by the threat actor rather than compromise ([The Hacker News, 2026-07-06](https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html)). SecurityWeek's coverage of the same Sysdig telemetry frames it as active exploitation and omits that caveat ([SecurityWeek, 2026-07-07](https://www.securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn)) — so the "actively exploited" characterisation is itself contested across the very reporting NCSC-CH cites. NCSC-CH's advisory does not resolve the gap with its own data, so the defensible read is "scanning confirmed, compromise unconfirmed" — which changes nothing about the remediation priority: a public PoC exists for a pre-auth admin-takeover on software Sysdig counts at roughly 6,200 internet-facing instances, and self-hosted Gitea is common across DACH/EU public-sector and academic DevOps.

**Defender takeaway:** the national-CERT status change is the signal to move exposed Docker instances to the front of the patch queue if they were not already remediated in June; the detection concept (spoofed `X-WEBAUTH-USER` from a non-trusted-proxy source IP) is unchanged from the original entry.
