📦 Soft Serve

by Charm

🔍 What is Soft Serve?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-24058

CRITICAL CVSS 9.8 Jan 22, 2026

Soft Serve versions 0.11.2 and below have a critical authentication bypass vulnerability that allows attackers to impersonate any user, including administrators, during SSH authentication. This occurs...

CVE-2025-64522

CRITICAL CVSS 9.1 Nov 10, 2025

Soft Serve versions before 0.11.1 have a server-side request forgery (SSRF) vulnerability where repository administrators can create webhooks that target internal services, private networks, and cloud...

CVE-2025-22130

HIGH CVSS 8.8 Jan 8, 2025

CVE-2025-22130 is a path traversal vulnerability in Soft Serve Git server that allows non-admin users to access and take over other users' repositories. Attackers can modify, delete, and control repos...