Vulnerability Management Critical Gitea flaw allows authentication bypass via single HTTP header July 9, 2026 Share By SC Staff Attackers are actively exploiting a critical authentication bypass vulnerability in Gitea's official Docker images, tracked as CVE-2026-20896. This flaw, with a CVSS score of 9.8, allows unauthorized access to repositories and sensitive data with the transmission of a single HTTP header, as reported by Security Affairs. The vulnerability stems from an insecure default configuration in Gitea's official Docker images (versions prior to 1.26.3) where the "REVERSE_PROXY_TRUSTED_PROXIES" setting is set to "*". This wildcard setting incorrectly trusts any IP address as a legitimate reverse proxy. Consequently, attackers can send a crafted "X-WEBAUTH-USER" HTTP header, impersonating any user, including administrators, without needing a password or token. This bypasses authentication entirely, granting access to private repositories, source code, API keys, database credentials, and deploy keys. While the flaw specifically affects the official Docker images, standard or self-built Gitea installations with secure default configurations are not impacted. Sysdig identified approximately 6,200 internet-exposed Gitea instances, though the exact number of vulnerable systems is unknown. Users are strongly advised to update to Gitea version 1.26.3 or later immediately. Source: Security Affairs SC Staff Related Vulnerability Management HP DeskJet 2800 series printers vulnerable to sensitive data exposure SC Staff July 9, 2026 Vulnerability Management BeyondTrust warns of critical flaws in remote access software SC Staff July 9, 2026 The vulnerabilities, tracked as CVE-2026-40138 and CVE-2026-40139, affect specific versions of BeyondTrust's RS and PRA software. Vulnerability Management Microsoft releases patch for Defender zero-day vulnerability RoguePlanet SC Staff July 9, 2026 The vulnerability, tracked as CVE-2026-50656, was revealed by a security researcher using the handle "Nightmare Eclipse." Related Events Cybercast Why Mythos is the cybersecurity crisis we need Wed Jul 22 Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds