MEDIUMVulnerability

CVE-2026-90679

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming ActivityPub activity was produced by the key belonging to the actor named in the activity body. The signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, but the inbox activity handlers subsequently read the acting identity from the attacker-controlled JSON body without binding it to the verified signing key. Additionally, the signed Digest header is not recomputed against the received request body. A remote attacker who hosts a single valid ActivityPub actor and keypair can therefore submit signature-valid activities attributed to any actor identity they name.

Properties

severity
MEDIUM
score
4.3
cve_id
CVE-2026-90679
signal_observed_at
2026-09-21T23:07:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
published_at
2026-09-13T04:17:25.417
last_modified
2026-09-15T18:19:37.863

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Use of Less Trusted Source

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90679 — Ninja Signal Threat Intelligence | Ninja Signal