Forgejo

4 known vulnerabilities in Forgejo, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-90679 CVSS 4.3 medium Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does…
  • CVE-2026-89151 CVSS 3.5 low Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.
  • CVE-2026-89094 CVSS 9.9 critical Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in…
  • CVE-2026-82556 CVSS 2.1 low A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file…