Charm maintains a narrowly scoped portfolio centered on the Soft Serve and Charm products, which appear to be collaboration or version-control infrastructure tools, and its vulnerability footprint skews strongly toward critical-severity outcomes. The recurring exposure clusters around server-side request forgery, path traversal, authentication bypass, and information disclosure weaknesses that are typical of web-facing service architectures where request handling and access control are security-critical. Defenders should prioritize patching instances of these products and audit their network exposure; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Charm over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41589CRITICAL Wish is an SSH server with defaults and a collection of middlewares. From version 2.0.0 to before version 2.0.1, the SCP middleware in charm.land/wish/v2 is vulnerable to path trav | May 7, 2026 | 9.6 | 36 | NO | NO |
CVE-2026-30832CRITICAL Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to | Mar 7, 2026 | 9.1 | 32 | NO | NO |
CVE-2022-29180CRITICAL A vulnerability in which attackers could forge HTTP requests to manipulate the `charm` data directory to access or delete anything on the server. This has been patched and is avail | May 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-24058CRITICAL Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate | Jan 22, 2026 | 9.8 | 30 | NO | NO |
CVE-2025-64522HIGH Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administ | Nov 10, 2025 | 7.6 | 24 | NO | NO |
CVE-2025-22130HIGH Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's reposit | Jan 8, 2025 | 8.8 | 24 | NO | NO |
CVE-2026-33353MEDIUM Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user t | Mar 24, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-43809HIGH Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to byp | Oct 4, 2023 | 7.5 | 23 | NO | NO |
CVE-2026-22253MEDIUM Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with | Jan 8, 2026 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Charm.
Media articles that mention a CVE ID that affects a product developed by Charm — matched by CVE ID, not by vendor name.