VendorsCharmsoft_serveall versions
Vulnerabilities

Charm Soft Serve

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-24058
Soft Serve has Critical Authentication Bypass
Published 2026-01-22 · Analyzed
9.8EPSS 0.006
CVE-2026-30832
Soft Serve: SSRF via unvalidated LFS endpoint in repo import
Published 2026-03-07 · Analyzed
9.1EPSS 0.004
CVE-2025-64522
Soft Serve is vulnerable to SSRF through its Webhooks
Published 2025-11-10 · Analyzed
9.1EPSS 0.003
CVE-2025-22130
Soft Serve allows path traversal attacks
Published 2025-01-08 · Analyzed
8.8EPSS 0.007
CVE-2023-43809
Soft Serve Public Key Authentication Bypass Vulnerability when Keyboard-Interactive SSH Authentication is Enabled
Published 2023-10-04 · Modified
7.5EPSS 0.009
CVE-2026-33353
Soft Serve: Authenticated repo import can clone server-local private repositories
Published 2026-03-24 · Analyzed
7.1EPSS 0.004
CVE-2026-22253
Soft Serve is missing an authorization check in LFS lock deletion
Published 2026-01-08 · Analyzed
5.4EPSS 0.003