IncidentGitea Header Injection: 13 Days to Exploitation
On January 17, 2025, Gitea maintainers disclosed CVE-2026-20896, a critical authentication bypass in their Docker images. This flaw allows anyone to send a crafted HTTP header and gain admin access to














