<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Gitea Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Gitea.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>Critical Gitea Flaw Under Active Exploitation, Researchers Warn</title><link>https://securityweek.com/critical-gitea-flaw-under-active-exploitation-researchers-warn</link><guid isPermaLink="false">cst-545</guid><description>A critical vulnerability in Gitea (CVE-2026-20896) allows attackers to bypass authentication by manipulating a single HTTP header, granting access to repositories and secrets. Researchers have confirmed the flaw is under active exploitation in the wild.</description><pubDate>Tue, 07 Jul 2026 17:17:19 GMT</pubDate></item><item><title>Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure</title><link>https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html</link><guid isPermaLink="false">cst-486</guid><description>Threat actors have begun probing a critical vulnerability in Gitea Docker images (CVE-2026-20896, CVSS 9.8) just 13 days after its disclosure. The flaw allows unauthenticated users to bypass authentication by spoofing the X-WEBAUTH-USER header, enabling elevated privilege access to the DevOps platform.</description><pubDate>Mon, 06 Jul 2026 16:28:59 GMT</pubDate></item></channel></rss>