漏洞描述
The official Gitea Docker image through version 1.26.2 ships with REVERSE_PROXY_TRUSTED_PROXIES set to a wildcard, causing Gitea to trust reverse-proxy authentication headers (X-WEBAUTH-USER) from any source IP instead of restricting trust to the configured reverse proxy. When reverse-proxy authentication is enabled, an unauthenticated remote attacker can impersonate any existing user, including an administrator, by sending the target username in the X-WEBAUTH-USER header.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/go-gitea/gitea/security/advisories/GHSA-f75j-4cw6-rmx4↗blog.gitea.comhttps://blog.gitea.com/release-of-1.26.3-and-1.26.4/↗github.comhttps://github.com/go-gitea/gitea/pull/38151↗www.ionix.iohttps://www.ionix.io/threat-center/cve-2026-20896/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-20896↗