System running
Last check: 2026-09-29 05:30:42 | Auto-updates every hour
756 PoCs
CybersecPlayground | The ultimate platform for cybersecurity learning & Bug Bounty Resources

CVE-CVE-2026-20896

Severity
CRITICAL
CVSS Score
9.8
Description

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled....

PoCs for CVE-CVE-2026-20896

CVE-2026-20896-Gitea-Authentication-Bypass
Authentication Bypass Python 0
judgedbykira 2026-08-15
Master Cybersecurity | Join CybersecPlayground for Cybersecurity Learning & Bug Bounty Resources