CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-20896: Gitea Reverse-Proxy Authentication Bypass

July 6, 2026

A critical reverse-proxy authentication bypass in Gitea Docker images, patched in June 2026. Threat actors were observed probing the flaw 13 days after disclosure.