Hackers are actively exploiting a critical authentication bypass vulnerability in the official Docker image for Gitea, a popular open-source alternative to GitHub and GitLab. The flaw, tracked as CVE-2026-20896, allows unauthenticated attackers to impersonate any user, including administrators, by sending a single spoofed HTTP header. Security researchers at Sysdig confirm