Elektrine lite

← Feed

@forgejo@floss.social

Post #1811506

2026-04-30 15:11 UTC

The author of the recent 'Carrot disclosure' blog post has contacted the Forgejo Security team with their findings. The issues raised concern defence-in-depth improvements and denial-of-service risks. There is no known RCE exploit possible without internal server credentials. 1/2

Replies (4)

  • @siv@mastodon.praxis.red 2026-04-30 15:36

    @forgejo@floss.social please link the referenced blog post? Thanks!

    Open ##1811505

  • @forgejo@floss.social 2026-04-30 15:11

    We believe these findings can be addressed publicly. The security team will open issues where approaches to implement new defensive measurements will be discussed, we believe there's no single answer and as such appreciate the opinion of other Forgejo contributors on this matter. 2/2

    Open ##2045786

  • @Ember@blobfox.coffee 2026-04-30 20:22

    @forgejo@floss.social and all of this could have been avoided if they'd just contacted forgejo in the first place

    Open ##3649820

  • @jzb@hachyderm.io 2026-05-14 13:08

    @forgejo@floss.social Could you elaborate on what "internal server credentials" you're talking about? There is some speculation about whether that means a user account on a Forgejo instance or if it means (as I read it) "internal" credentials that are only available if a user has actual server access. But it's ambiguous, which is bad for folks who are trying to understand the actual security implications. A more detailed explanation would be great. Thanks!

    Open ##3649826