One HTTP Header, Full Admin Access: Gitea's June 2026 Security Release Explained
Gitea 1.26.3 and 1.26.4 addressed a dense security release window, including a 9.8 CRITICAL auth bypass exploitable with a single HTTP header. Here's what broke and how to fix it.