Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68971

Опубликовано: 16 мар. 2026
Источник: redhat
CVSS3: 6.5

Описание

A flaw was found in Forgejo. A remote attacker could exploit this vulnerability in the attachment component by uploading a multi-gigabyte file attachment, such as to an issue or a release. This could lead to a Denial of Service (DoS), making the service unavailable to legitimate users.

Отчет

This MODERATE vulnerability in Forgejo allows authenticated users to cause denial of service by uploading excessively large file attachments. Exploitation requires low privileges (valid account) and is network-accessible. Impact is high availability loss due to resource exhaustion. Affects Forgejo through version 13.0.3.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2448387forgejo: Forgejo: Denial of Service via large file attachment upload

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
18 дней назад

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).

CVSS3: 6.5
debian
18 дней назад

In Forgejo through 13.0.3, the attachment component allows a denial of ...

CVSS3: 7.5
github
18 дней назад

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).

6.5 Medium

CVSS3