CVE-2025-68971

Published: Mar 16, 2026 Last Modified: Mar 16, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=291973
https://codeberg.org/forgejo/forgejo
https://zenodo.org/records/18945481