
this is a modified POC of rz1027 for CVE-2026-20896
This repository provides a small, self-contained lab for exploring the CVE-2026-20896 issue in a controlled and authorized environment.
The lab includes:
This project is intended strictly for education, research, and authorized security testing. It should only be used against systems you own or are explicitly authorized to test.
Start the lab environment:
docker compose up -d
Verify that the service is reachable:
python3 detect.py http://localhost:3000
Run the proof-of-concept:
python3 poc.py http://localhost:3000 admin
The vulnerability is related to reverse-proxy authentication handling in Gitea. When reverse-proxy authentication is enabled, Gitea can trust the X-WEBAUTH-USER header if the trusted proxy configuration is too permissive.
In a vulnerable setup, an attacker who can reach the service directly may be able to spoof this header and impersonate another user. The PoC demonstrates that behavior in a controlled environment and exports cookies that can be imported into a browser for testing purposes.
This repository is provided for educational and authorized security testing only.
By using this project, you agree that:
The authors and contributors assume no liability for misuse or damage.
The original reference for the detection logic and lab setup is:
This repository uses that work as a reference for the lab environment and detection approach. The PoC script in poc.py has been customized and is presented as my own implementation.
Please preserve attribution when reusing or adapting this work.
This project is licensed under the MIT License. See LICENSE for details.