9.8
CVE-2026-20896
- EPSS 0.78%
- Published 03.07.2026 20:19:29
- Last modified 07.07.2026 18:16:35
- CVE watchlists
- Open
Gitea Docker image trusts spoofable reverse-proxy headers by default
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
Data is provided by the CVE programme from a CVE Numbering Authority (CNA) (unstructured).
VendorGitea
≫
Product
Gitea Open Source Git Server
Default Statusunaffected
Version <=
1.26.2
Version
0
Status
affected
| Type | Source | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.78% | 0.516 |
| Source | Base Score | Exploit Score | Impact Score | Vector string |
|---|---|---|---|---|
| 88ee5874-cf24-4952-aea0-31affedb7ff2 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
A VulnDex account is required to access Vulnerability Intelligence.
A VulnDex account is required to access Vulnerability Intelligence.
A VulnDex account is required to access Vulnerability Intelligence.
https://github.com/go-gitea/gitea/pull/38151
https://github.com/go-gitea/gitea/releases/tag/v1.26.3
https://blog.gitea.com/release-of-1.26.3-and-1.26.4/
https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4