PT-2026-90787 · Forgejo · Forgejo

CVE-2026-90679

·

Published

2026-09-13

·

Updated

2026-09-22

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Forgejo versions 13.0.0 through 16.0.4
Description An identity spoofing issue exists when [federation] ENABLED = true is configured. The system fails to verify that the HTTP Signature of an incoming ActivityPub activity was generated by the key associated with the actor specified in the activity body. While the signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, the inbox activity handlers read the acting identity from the JSON body without binding it to the verified signing key. Furthermore, the signed Digest header is not recomputed against the received request body. This allows a remote attacker with a valid ActivityPub actor and keypair to submit activities attributed to any actor identity. This issue affects identity integrity but does not permit account takeover or content modification.
Recommendations Update Forgejo to a version later than 16.0.4. As a temporary mitigation, set [federation] ENABLED = false to disable the affected federation functionality.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90679

Affected Products

Forgejo