Response playbooks, investigation guides, and Atomic Red Team tests are Pro-only. Upgrade to unlock the full detection package for CVE-2026-20896.

Upgrade to Pro
CVE-2026-20896 Google Chronicle · YARA-L

Detect Gitea Docker REVERSE_PROXY_TRUSTED_PROXIES Wildcard Allows X-WEBAUTH-USER Auth Bypass (CVE-2026-20896) in Google Chronicle

The official Gitea Docker image ships with REVERSE_PROXY_TRUSTED_PROXIES set to * by default. Because Gitea's reverse-proxy authentication feature trusts the X-WEBAUTH-USER header from any source claiming to be a trusted proxy, an unauthenticated attacker with direct network access to the Gitea HTTP listener (bypassing any intended reverse proxy) can set this header to impersonate any username, including admin accounts, and obtain a fully authenticated session without credentials. Affects code.gitea.io/gitea < 1.26.3. This detection identifies HTTP requests to Gitea that carry X-WEBAUTH-USER (or similar reverse-proxy auth headers) originating from IP addresses outside the expected reverse-proxy/load-balancer CIDR, as well as anomalous successful authentications tied to reverse-proxy auth with no corresponding upstream proxy log entry.

MITRE ATT&CK

Tactic
Initial Access Privilege Escalation Defense Evasion

YARA-L Detection Query

Google Chronicle (YARA-L)
yaral
rule gitea_webauth_user_header_untrusted_source {
  meta:
    author = "detection-engineering"
    description = "Detects X-WEBAUTH-USER header on Gitea requests from untrusted source IP, indicating CVE-2026-20896 exploitation"
    severity = "CRITICAL"
  events:
    $e.metadata.event_type = "NETWORK_HTTP"
    $e.target.application = "gitea"
    $e.network.http.request_headers["x-webauth-user"] != ""
    not net.ip_in_range_cidr($e.principal.ip, "10.0.0.0/8")
    not net.ip_in_range_cidr($e.principal.ip, "172.16.0.0/12")
    not net.ip_in_range_cidr($e.principal.ip, "192.168.0.0/16")
  condition:
    $e
}
critical severity medium confidence

Chronicle UDM rule flagging Gitea HTTP requests with the X-WEBAUTH-USER header set from source IPs outside trusted internal proxy ranges.

Data Sources

Gitea HTTP access logs ingested as NETWORK_HTTP UDM events

Required Tables

NETWORK_HTTP

False Positives & Tuning

  • Untracked but legitimate proxy IP outside baseline CIDR list
  • Internal NAT/load balancer obscuring true proxy source IP
  • Security tooling replaying captured proxy headers for testing

Other platforms for CVE-2026-20896


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Direct X-WEBAUTH-USER header injection against Gitea container

    Expected signal: HTTP request log entry on the Gitea/reverse-proxy access log showing X-WEBAUTH-USER header with source IP of the test host

  2. Test 2Verify REVERSE_PROXY_TRUSTED_PROXIES wildcard misconfiguration

    Expected signal: Command execution logged in container audit/history; no network telemetry generated

  3. Test 3Impersonate arbitrary user and attempt privileged API call

    Expected signal: Gitea audit log entry for an admin API call sourced from an impersonated session; access log entry with X-WEBAUTH-USER header from untrusted source IP

Unlock playbooks & atomic tests with Pro

Get the full detection package for CVE-2026-20896 — response playbook and atomic red team tests, plus investigation guidance and hunting queries.

df00tech Pro — £29/user/month

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections