CVE-2025-68971: Medium severity forgejo/forgejo vulnerability
Published Mar 16, 2026
·Updated
In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).
Affected Software
1 affected component
forgejo/forgejo<=13.0.3
Event History
Mar 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Dec 27, 58178
Event
via NVD·09:33 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-68971?
CVE-2025-68971 has a medium severity rating of 6.5 according to the CVSS v3.1.
2
How do I fix CVE-2025-68971?
To mitigate CVE-2025-68971, limit the maximum file size for attachments in your Forgejo installation.
3
What type of vulnerability is CVE-2025-68971?
CVE-2025-68971 is a denial of service vulnerability affecting the attachment component of Forgejo.
4
Which versions of Forgejo are affected by CVE-2025-68971?
CVE-2025-68971 affects all versions of Forgejo through 13.0.3.
5
What impact does CVE-2025-68971 have on system performance?
CVE-2025-68971 can lead to denial of service by allowing the upload of multi-gigabyte file attachments, potentially overwhelming system resources.