Hackers exploit critical auth bypass in Gitea Docker image
…The security flaw is an authentication bypass vulnerability, tracked as CVE-2026-20896 , that affects deployments using the default configuration, where reverse proxy authentication headers such as X-WEBAUTH-USER are enabled…