Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Charm

First CVE: May 7, 2022Active for: 4 yearsTotal CVEs: 9

Charm maintains a narrowly scoped portfolio centered on the Soft Serve and Charm products, which appear to be collaboration or version-control infrastructure tools, and its vulnerability footprint skews strongly toward critical-severity outcomes. The recurring exposure clusters around server-side request forgery, path traversal, authentication bypass, and information disclosure weaknesses that are typical of web-facing service architectures where request handling and access control are security-critical. Defenders should prioritize patching instances of these products and audit their network exposure; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Charm over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 7, 2022
4 years ago
Most Recent CVE
May 7, 2026
78 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-41589CRITICAL
Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path trav
May 7, 20269.636NONO
CVE-2026-30832CRITICAL
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to
Mar 7, 20269.132NONO
CVE-2022-29180CRITICAL
A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. This has been patched and is avail
May 7, 20229.831NONO
CVE-2026-24058CRITICAL
Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate
Jan 22, 20269.830NONO
CVE-2025-64522HIGH
Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administ
Nov 10, 20257.624NONO
CVE-2025-22130HIGH
Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's reposit
Jan 8, 20258.824NONO
CVE-2026-33353MEDIUM
Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user t
Mar 24, 20266.523NONO
CVE-2023-43809HIGH
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to byp
Oct 4, 20237.523NONO
CVE-2026-22253MEDIUM
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with
Jan 8, 20265.420NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
22%
33%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (55.6%)
High1 (11.1%)
None3 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Charm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Charm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Charm's Products

View all 1 CNAs →

Top CWEs