{"id":"CVE-2026-20896","title":"Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.","summary":"Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-284"],"published":"2026-07-03","updated":"2026-07-03","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20896","references":[{"url":"https://blog.gitea.com/release-of-1.26.3-and-1.26.4/","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/pull/38151","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/releases/tag/v1.26.3","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"},{"url":"https://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4","label":"88ee5874-cf24-4952-aea0-31affedb7ff2"}],"tags":["nvd","exploit-available"],"epss":0.02755,"epssPercentile":0.85519,"ingestedAt":"2026-07-04T13:56:12.041Z","exploits":{"github":6,"githubRepos":["https://github.com/szybnev/cve-2026-20896-gitea-poc","https://github.com/rz1027/CVE-2026-20896","https://github.com/XaocZenon/CVE-2026-20896"],"nuclei":["CVE-2026-20896"],"checkedAt":"2026-09-21T15:28:26.348Z"},"exploitAvailable":true,"slug":"CVE-2026-20896","body":"## Overview\n\nGitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.6,"exploitation":12,"ransomware":0},"changes":[{"seq":5003,"id":"CVE-2026-20896","ts":1788887227254,"field":"exploit_available","old":"false","new":"true"},{"seq":3886,"id":"CVE-2026-20896","ts":1788886358243,"field":"exploit_available","old":"true","new":"false"},{"seq":2708,"id":"CVE-2026-20896","ts":1788883023832,"field":"exploit_available","old":"false","new":"true"},{"seq":1737,"id":"CVE-2026-20896","ts":1788882427937,"field":"exploit_available","old":"true","new":"false"},{"seq":843,"id":"CVE-2026-20896","ts":1788881861243,"field":"exploit_available","old":"false","new":"true"},{"seq":170,"id":"CVE-2026-20896","ts":1787603608507,"field":"epss","old":"0.62381","new":"0.02755"},{"seq":155,"id":"CVE-2026-20896","ts":1787257292874,"field":"epss","old":"0.31809","new":"0.62381"},{"seq":83,"id":"CVE-2026-20896","ts":1784920468669,"field":"epss","old":"0.00783","new":"0.31809"}]}