{"id":1619,"date":"2026-07-06T17:19:58","date_gmt":"2026-07-06T17:19:58","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1619"},"modified":"2026-07-06T17:19:58","modified_gmt":"2026-07-06T17:19:58","slug":"threat-actors-probe-gitea-docker-flaw-cve-2026-20896-13-days-after-disclosure","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1619","title":{"rendered":"Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 06, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ DevOps<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEge0sNgi3moDw0JpFy3UdFB6bK0oxjaqc8ORZFecu5QqxA_wgpoWT1t56L9u2wScSkxYHP2aLO3N01yCPd8IkTBEyc_MvxIaG6BKzneB0LcXuwO_nEorvNvyvuEL3Krp003q6xOF0gePQCXN_bDswxBIhqV7q89_HY9mIxJ5ySShQwtU_jSa9FQnt0tq0RU\/s1700-e365\/admin.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:share:7479652556885954560\/\">according to Sysdig<\/a>.<\/p>\n<p>The vulnerability in question is <b><a href=\"https:\/\/github.com\/go-gitea\/gitea\/security\/advisories\/GHSA-f75j-4cw6-rmx4\">CVE-2026-20896<\/a><\/b> (CVSS score: 9.8), a vulnerability that stems from the DevOps platform trusting the \u00abX-WEBAUTH-USER\u00bb header from any source IP address, effectively allowing an unauthenticated internet client to get elevated access.<\/p>\n<p>In a statement shared with The Hacker News via email, security researcher Ali Mustafa (@rz1027), who is credited with <a href=\"https:\/\/github.com\/rz1027\/CVE-2026-20896\">discovering and reporting<\/a> the flaw, said the Gitea Docker images shipped an \u00abapp.ini\u00bb template that hard-codes \u00abREVERSE_PROXY_TRUSTED_PROXIES = *\u00bb by default. The \u00ab<a href=\"https:\/\/docs.gitea.com\/administration\/config-cheat-sheet\">app.ini<\/a>\u00bb file is a core configuration file for managing server parameters, database connections, security behavior, and application settings.<\/p>\n<p>\u00abWith reverse-proxy login enabled, that wildcard trusts every source IP, so anyone who could reach the port could send an X-WEBAUTH-USER header and be authenticated as any user, with no password and no token,\u00bb Mustafa explained. \u00abWith auto-registration on, an admin username gives admin.\u00bb<\/p>\n<p>It&#8217;s worth noting that the documented safe value for the \u00abREVERSE_PROXY_TRUSTED_PROXIES\u00bb internal variable is \u00ab127.0.0.0\/8,::1\/128,\u00bb meaning only localhost aka the loopback interface, is allowed as a trusted proxy server. However, the official Docker image doesn&#8217;t use this default, hard-coding \u00ab*\u00bb instead. In other words, the allowlist check is as good as not having it.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-2\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhr7HGzx4ULDSqwnN820pPGxlPxqqVxKgIrI5II1iWdspOL6yHZsdB5lWoXU3LmhIU4dtnph89fLZ0CxrQSs-ufs6Mo4eD-d-Cpx-DsV1G15eC-phLACF7hyaKSIH1zIdj3AuD7lHSHnVelmKVMoVV-_zvtJuodsSIDKu6uSRfU6fZBkO-2PERqKSfIn6dA\/s728-e100\/sygnia-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Thus, when an admin sets \u00abENABLE_REVERSE_PROXY_AUTHENTICATION = true\u00bb to put Gitea behind an authenticating reverse proxy and leaves the \u00abREVERSE_PROXY_TRUSTED_PROXIES\u00bb setting to its default value, it allows a X-WEBAUTH-USER custom HTTP header from any source IP that can reach the container.<\/p>\n<p>\u00abAny process that can reach the Gitea container&#8217;s HTTP port directly \u2013 not through the intended authenticating proxy \u2013 can impersonate any user whose login name is known or guessable,\u00bb according to Gitea&#8217;s advisory. \u00abAdmin accounts (admin, gitea_admin, etc.) are the obvious targets.\u00bb<\/p>\n<p>The vulnerability affects Gitea Docker images versions before and including 1.26.2. It has been addressed in <a href=\"https:\/\/blog.gitea.com\/release-of-1.26.3-and-1.26.4\/\">version 1.26.3<\/a> released late last month, with the \u00ab*\u00bb wildcard now removed and reverse-proxy authentication made opt-in.<\/p>\n<p>Cloud security company Sysdig has since revealed it detected the first in-the-wild exploitation attempt 13 days after public disclosure of the vulnerability. There are about 6,200 internet-facing Gitea instances.<\/p>\n<p>\u00abSo far, the activities have been related to initial investigation by the threat actor,\u00bb Michael Clark, senior director of threat research at Sysdig, told The Hacker News.<\/p>\n<p>\u00abWhile we saw the first action from an IP from the ProtonVPN service, 159.26.98[.]241\u00a0 it has not so far progressed to any exploitation or attack progress. We think this is because we have seen this one early before it has had the chance to develop beyond that initial phase.\u00bb<\/p>\n<p>Given the severity of the issue, it&#8217;s essential that users apply the fixes as soon as possible for optimal protection.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 06, 2026Vulnerability \/ DevOps Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The vulnerability in&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1620,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[545,2373,1685,799,136,70,1808,352,171],"class_list":["post-1619","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-actors","tag-cve202620896","tag-days","tag-disclosure","tag-docker","tag-flaw","tag-gitea","tag-probe","tag-threat"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1619"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1619\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1620"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}