Where
-Infinity
0

Sysdig just published telemetry confirming active probing of CVE-2026-20896 (Gitea Docker auth bypass) 13 days after disclosure. First observed attempt came from ProtonVPN egress 159.26.98\[.\]241. Detection for the X-WEBAUTH-USER header injection was already live in my repo before that dropped.

Since my last post, bikini pushed five new exploitarium entries and I’ve added coverage for all of them:

\-curl SMTP CRLF injection \-NodeBB ActivityPub UID spoofing \-Next.js unstable\\\cache object argument collision \-libarchive ZIP debuginfod size boundary bypass \-Pillow ImageCms OOB write

Repo is now 55 KQL rules across 23 product folders. All written for Sentinel / Defender XDR. Language translation on detections.ai handles other stacks.

Intel report: https://systemtwosecurity.com/share/inspiration/VNJMKFVM

GitHub: https://github.com/Ethan-Andrews/Exploitarium-Detections

The Gitea finding is being actively probed. If you’re running any default Gitea Docker deployments that haven’t patched to 1.26.3 yet, that’s the one to prioritize.

Happy to discuss detection logic or the specific technique in the comments.

First published (updated )
Social
reddit

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203