PT-2026-90787 · Forgejo · Forgejo
CVE-2026-90679
·
Published
2026-09-13
·
Updated
2026-09-22
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Forgejo versions 13.0.0 through 16.0.4
Description
An identity spoofing issue exists when
[federation] ENABLED = true is configured. The system fails to verify that the HTTP Signature of an incoming ActivityPub activity was generated by the key associated with the actor specified in the activity body. While the signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, the inbox activity handlers read the acting identity from the JSON body without binding it to the verified signing key. Furthermore, the signed Digest header is not recomputed against the received request body. This allows a remote attacker with a valid ActivityPub actor and keypair to submit activities attributed to any actor identity. This issue affects identity integrity but does not permit account takeover or content modification.Recommendations
Update Forgejo to a version later than 16.0.4.
As a temporary mitigation, set
[federation] ENABLED = false to disable the affected federation functionality.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forgejo