Hackers Exploit Critical Auth Bypass in Gitea Docker Image
Attackers are hijacking Gitea instances by impersonating any user, including admins, through the official Docker image.
The flaw sits in how the image handles authentication. Actively exploited in the wild, it lets unauthenticated attackers take over accounts without credentials.
Affects anyone running Gitea via the official Docker image. Self-hosted Git setups on standard container deployments are directly exposed.
Exploitation attempts hit roughly 1,900 servers in the initial wave.
