Bug 2532933 - CVE-2026-90679 forgejo: Forgejo: Identity spoofing via unverified ActivityPub signatures [fedora-all]
Summary: CVE-2026-90679 forgejo: Forgejo: Identity spoofing via unverified ActivityPub...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: forgejo
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Fedora Infrastructure SIG
QA Contact:
URL:
Whiteboard: {"flaws": ["7e743838-3570-48c6-b78c-1...
Depends On:
Blocks: CVE-2026-90679
TreeView+ depends on / blocked
 
Reported: 2026-09-14 07:22 UTC by Vladimir Vasilev
Modified: 2026-09-14 07:22 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-09-14 07:22:51 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming ActivityPubactivity was produced by the key belonging to the actor named in the activity body. The signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, but the inbox activity handlers subsequently read the acting identity from the attacker-controlled JSON body without binding it to the verified signing key. Additionally, the signed Digest header is not recomputed against the received request body. A remote attacker who hosts a single valid ActivityPub actor and keypair can therefore submit signature-valid activities attributed to any actor identity they name.


Note You need to log in before you can comment on or make changes to this bug.