⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

Gitea Docker Images Patched for Critical Authentication Bypass

July 6, 2026

Gitea Docker images versions before 1.26.3 are vulnerable to CVE-2026-20896, which allows unauthenticated access via a trusted reverse proxy header. The fix removes the wildcard trust and makes reverse-proxy authentication opt-in.