Gitea Docker image versions up to and including 1.26.2 use REVERSEPROXYTRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.
{
"cwe_ids": [
"CWE-284"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/20xxx/CVE-2026-20896.json",
"cna_assigner": "Gitea"
}