CVE-2026-90679 | Forgejo up to 16.0.4 ActivityPub reqsignature.go signature verification

SecurityVulns

A vulnerability marked as problematic has been reported in Forgejo up to 16.0.4. The affected element is an unknown function of the file routers/api/v1/activitypub/reqsignature.go of the component ActivityPub. The manipulation leads to improper verification of cryptographic signature.

This vulnerability is documented as CVE-2026-90679. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More