Gitea Docker images versions before 1.26.3 are vulnerable to CVE-2026-20896, which allows unauthenticated access via a trusted reverse proxy header. The fix removes the wildcard trust and makes reverse-proxy authentication opt-in.
Gitea Docker images versions before 1.26.3 are vulnerable to CVE-2026-20896, which allows unauthenticated access via a trusted reverse proxy header. The fix removes the wildcard trust and makes reverse-proxy authentication opt-in.