CVE-2026-20896: The Gitea Docker Flaw That Takes One Header to Own Your Server
A critical Docker image default in Gitea lets attackers gain admin access with a single HTTP header. Here's how CVE-2026-20896 works, how to check if you're vulnerable, and how to fix it in five minutes.