Soft Serve
Vendor:
First CVE: Oct 4, 2023 · Active for 2 years
7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 67% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Soft Serve over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2023
2 years ago
Most Recent CVE
Mar 24, 2026
122 days ago
CVE Severity & Scoring
Soft Serve7 CVEs
29%
43%
29%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (57.1%)
High1 (14.3%)
None2 (28.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30832CRITICAL Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to | Mar 7, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-24058CRITICAL Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate | Jan 22, 2026 | 9.8 | 30 | NO | NO |
CVE-2025-64522HIGH Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administ | Nov 10, 2025 | 7.6 | 24 | NO | NO |
CVE-2025-22130HIGH Soft Serve is a self-hostable Git server for the command line. Prior to 0.8.2 , a path traversal attack allows existing non-admin users to access and take over other user's reposit | Jan 8, 2025 | 8.8 | 24 | NO | NO |
CVE-2026-33353MEDIUM Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an authorization flaw in repo import allows any authenticated SSH user t | Mar 24, 2026 | 6.5 | 23 | NO | NO |
CVE-2023-43809HIGH Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerability in Soft Serve could allow an unauthenticated, remote attacker to byp | Oct 4, 2023 | 7.5 | 23 | NO | NO |
CVE-2026-22253MEDIUM Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with | Jan 8, 2026 | 5.4 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Soft Serve
Top CWEs
Versions
No cataloged versions.