CVE-2025-68971
Description
A flaw was found in Forgejo. A remote attacker could exploit this vulnerability in the attachment component by uploading a multi-gigabyte file attachment, such as to an issue or a release. This could lead to a Denial of Service (DoS), making the service unavailable to legitimate users.
Statement
This MODERATE vulnerability in Forgejo allows authenticated users to cause denial of service by uploading excessively large file attachments. Exploitation requires low privileges (valid account) and is network-accessible. Impact is high availability loss due to resource exhaustion. Affects Forgejo through version 13.0.3.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.