Charm
Charm Soft Serve: vulnerabilidades y CVE
Charm Soft Serve tiene 11 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses7
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-91773 | Media (5.3) | 0.34% | — | 15 sept 2026 | Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any… |
| CVE-2026-33353 | Alta (7.1) | 0.41% | — | 24 mar 2026 | Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user to clone a server-local Git repository,… |
| CVE-2026-30832 | Crítica (9.1) | 0.39% | — | 7 mar 2026 | Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by… |
| CVE-2026-24058 | Alta (8.1) | 0.59% | — | 22 ene 2026 | Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate any user (including admin) by… |
| CVE-2026-22253 | Media (5.4) | 0.31% | — | 8 ene 2026 | Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete… |
| CVE-2025-64522 | Alta (7.6) | 0.34% | — | 10 nov 2025 | Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting… |
| CVE-2025-64494 | Media (4.6) | 0.18% | — | 8 nov 2025 | Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g. names) and ANSI escape sequences are not being removed, which can… |
| CVE-2025-58355 | Alta (7.7) | 0.35% | — | 4 sept 2025 | Soft Serve is a self-hostable Git server for the command line. In versions 0.9.1 and below, attackers can create or override arbitrary files with uncontrolled data through its SSH API. This issue is fixed in version… |
| CVE-2025-22130 | Media (5.3) | 0.68% | — | 8 ene 2025 | Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's repositories. A malicious user then can… |
| CVE-2024-41956 | Alta (8.1) | 0.51% | — | 1 ago 2024 | Soft Serve is a self-hostable Git server for the command line. Prior to 0.7.5, it is possible for a user who can commit files to a repository hosted by Soft Serve to execute arbitrary code via environment manipulation… |
| CVE-2023-43809 | Alta (7.5) | 0.89% | — | 4 oct 2023 | Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to bypass public key authentication when… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.