Description
Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming ActivityPub activity was produced by the key belonging to the actor named in the activity body. The signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, but the inbox activity handlers subsequently read the acting identity from the attacker-controlled JSON body without binding it to the verified signing key. Additionally, the signed Digest header is not recomputed against the received request body. A remote attacker who hosts a single valid ActivityPub actor and keypair can therefore submit signature-valid activities attributed to any actor identity they name.
Published: 2026-09-13
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Identity Spoofing
Action: Patch
AI Analysis

Impact

Forgejo processes ActivityPub messages, but the logic that verifies the HTTP Signature does not enforce that the signing key matches the actor value declared in the activity JSON. The router validates the signature and then later handlers read the actor field from the payload without binding it to the verified key. This allows an external actor to sign an activity with a legitimate key and claim any actor identity of their choice, so the activity appears to come from that user. The flaw does not enable account takeover or modification of content; it only undermines identity integrity by misattributing activities.

Affected Systems

Forgejo releases 13.0.0 through 16.0.4 are vulnerable when federation is enabled by setting "[federation] ENABLED = true". Any installation that exposes its federation endpoints for ActivityPub communication is affected, regardless of the number of users or repositories.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate risk, while the EPSS score of less than 1% implies a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack can be carried out remotely by an adversary who can host a valid ActivityPub actor and key pair, sign messages, and send them to the federation endpoint. No privileged local access or elaborate social engineering is required.

Generated by OpenCVE AI on September 15, 2026 at 18:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest Forgejo version that includes the fixed signature verification logic.
  • If federation is not required, disable it by setting "[federation] ENABLED = false" so the server no longer accepts external ActivityPub activities.
  • Monitor the federation endpoint for anomalous actor names or repeated signature verification failures to detect possible spoofing attempts.

Generated by OpenCVE AI on September 15, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Title Forgejo ActivityPub Identity Spoofing Vulnerability

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Title Forgejo ActivityPub Identity Spoofing Vulnerability

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Forgejo Identity Spoofing via Unverified ActivityPub Signatures

Mon, 14 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Forgejo Identity Spoofing via Unverified ActivityPub Signatures

Sun, 13 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Forgejo ActivityPub Identity Spoofing Vulnerability

Sun, 13 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Title Forgejo ActivityPub Identity Spoofing Vulnerability

Sun, 13 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming ActivityPubactivity was produced by the key belonging to the actor named in the activity body. The signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, but the inbox activity handlers subsequently read the acting identity from the attacker-controlled JSON body without binding it to the verified signing key. Additionally, the signed Digest header is not recomputed against the received request body. A remote attacker who hosts a single valid ActivityPub actor and keypair can therefore submit signature-valid activities attributed to any actor identity they name. Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming ActivityPub activity was produced by the key belonging to the actor named in the activity body. The signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, but the inbox activity handlers subsequently read the acting identity from the attacker-controlled JSON body without binding it to the verified signing key. Additionally, the signed Digest header is not recomputed against the received request body. A remote attacker who hosts a single valid ActivityPub actor and keypair can therefore submit signature-valid activities attributed to any actor identity they name.

Sun, 13 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming ActivityPubactivity was produced by the key belonging to the actor named in the activity body. The signature verification in routers/api/v1/activitypub/reqsignature.go validates the request signature, but the inbox activity handlers subsequently read the acting identity from the attacker-controlled JSON body without binding it to the verified signing key. Additionally, the signed Digest header is not recomputed against the received request body. A remote attacker who hosts a single valid ActivityPub actor and keypair can therefore submit signature-valid activities attributed to any actor identity they name.
First Time appeared Forgejo
Forgejo forgejo
Weaknesses CWE-348
CPEs cpe:2.3:a:forgejo:forgejo:*:*:*:*:*:*:*:*
Vendors & Products Forgejo
Forgejo forgejo
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T17:17:34.738Z

Reserved: 2026-09-13T03:55:03.665Z

Link: CVE-2026-90679

cve-icon Vulnrichment

Updated: 2026-09-15T17:17:29.421Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T04:17:25.417

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-90679

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:00:15Z

Weaknesses
  • CWE-348

    Use of Less Trusted Source