CVE-2026-90679 Overview
CVE-2026-90679 is an identity spoofing vulnerability in Forgejo versions 13.0.0 through 16.0.4 when federation is enabled. The flaw resides in the ActivityPub inbox handling code. Signature verification in routers/api/v1/activitypub/reqsignature.go confirms that an incoming HTTP Signature is valid, but the subsequent inbox handlers extract the acting identity from the attacker-controlled JSON body. The handler never binds the actor named in the activity body to the key that signed the request. A remote attacker who controls one valid ActivityPub actor and keypair can submit signature-valid activities attributed to any actor identity. The issue affects identity integrity but does not permit account takeover or content modification.
Critical Impact
Any federated Forgejo instance can accept ActivityPub activities forged in the name of arbitrary remote actors, breaking federation identity guarantees.
Affected Products
- Forgejo 13.0.0 through 16.0.4 with [federation] ENABLED = true
- Forgejo ActivityPub inbox handlers in routers/api/v1/activitypub
- Federated Forgejo deployments accepting inbound ActivityPub traffic
Discovery Timeline
- 2026-09-13 - CVE-2026-90679 published to the National Vulnerability Database (NVD)
- 2026-09-15 - Last updated in NVD database
Technical Details for CVE-2026-90679
Vulnerability Analysis
The vulnerability is an insufficient verification of data authenticity issue [CWE-348] in Forgejo's ActivityPub federation implementation. Forgejo enforces HTTP Signature verification on inbound federation traffic through reqsignature.go. This middleware confirms the request signature matches the presented public key. The inbox activity handlers then parse the JSON payload and read the acting identity, such as the actor field, directly from that body. The handlers do not check that the actor URL resolves to a key matching the one that signed the request. Additionally, the signed Digest header is not recomputed against the received request body, so the payload can be altered independently of the signature. An attacker running a valid federated actor can therefore assert activities in the name of any other actor.
Root Cause
The root cause is a missing binding between the transport-layer authentication and the application-layer identity claim. Signature verification proves possession of a private key, but the code trusts the JSON body's actor field without verifying that the key belongs to that actor. The absent Digest recomputation compounds the flaw by leaving body integrity unenforced after signature validation.
Attack Vector
An attacker hosts a legitimate ActivityPub server with a valid actor and keypair. The attacker sends signed POST requests to the target Forgejo instance's inbox endpoints. The signature validates against the attacker's key, but the JSON payload names a different, victim actor. Forgejo processes the activity as if it originated from the impersonated identity. The attack requires network access and low privileges, matching the CVSS vector AV:N/AC:L/PR:L/UI:N. See the Codeberg Issue Comment for technical discussion.
Detection Methods for CVE-2026-90679
Indicators of Compromise
- Inbound ActivityPub POST requests to /api/v1/activitypub/* inbox endpoints where the signing key host does not match the actor field domain.
- Federation activity logs showing actors from domains different from the HTTP Signature keyId origin.
- Repeated inbox submissions from a single remote host asserting many distinct actor identities.
Detection Strategies
- Correlate the HTTP Signature keyId URL host with the actor URL host in each inbound ActivityPub activity and alert on mismatches.
- Recompute the Digest header against the request body at a proxy or WAF layer and flag activities where the values diverge.
- Baseline expected federation peers and alert when new remote hosts begin asserting activities for actors on unrelated domains.
Monitoring Recommendations
- Enable verbose logging on Forgejo federation routes and forward events to a centralized SIEM for correlation.
- Monitor for anomalous spikes in inbound Create, Follow, or Announce activities attributed to previously inactive remote actors.
- Track federation error rates and signature verification outcomes to identify probing behavior against inbox endpoints.
How to Mitigate CVE-2026-90679
Immediate Actions Required
- Upgrade Forgejo to a release beyond 16.0.4 that binds the signing key to the activity actor.
- If patching is not immediate, set [federation] ENABLED = false in app.ini to disable ActivityPub processing.
- Audit recent federation activity logs for signature and actor domain mismatches indicating prior spoofing attempts.
Patch Information
Refer to the Codeberg Issue Comment for upstream fix status. Administrators should track the Forgejo project's release notes and apply the version that enforces actor-to-key binding and Digest header recomputation.
Workarounds
- Disable federation by setting ENABLED = false in the [federation] section of app.ini and restart Forgejo.
- Restrict inbound access to /api/v1/activitypub/* endpoints using a reverse proxy allowlist of trusted federated peers.
- Deploy a WAF rule that rejects ActivityPub requests when the HTTP Signature keyId host does not match the JSON actor host.
# Disable Forgejo federation in app.ini
[federation]
ENABLED = false
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
