CRITICAL🇵🇱 Wersja polska

CVE-2025-64522

CVSS 9.1v3.1pub. 2025-11-10upd. 2025-12-31

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.

🤖 AI Analysis
How it works

The vulnerability results from lack of URL validation when creating webhooks in Soft Serve (CWE-918 — Server-Side Request Forgery). A repository administrator can configure a webhook pointing to any address, including resources accessible only on the server side. The server then executes an HTTP request to the specified address on its own behalf, allowing the attacker to probe internal infrastructure or retrieve sensitive data, such as tokens from cloud metadata endpoints (e.g., AWS IMDSv1).

Impact

An attacker with repository administrator privileges can gain access to internal network services not publicly accessible and read sensitive data, including credentials from cloud environment metadata endpoints. Limited modification of the state of internal services accepting HTTP requests is also possible.

Mitigation & patch

Soft Serve should be updated to version 0.11.1, which introduces webhook URL validation and eliminates the vulnerability. Patch available in the producer's GitHub repository (commit bb73b9a0eea0d902da4811420535842a4f9aae3b) and in the official release v0.11.1.

Who is affected

Soft Serve (Charm) — all versions prior to 0.11.1

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Charm Soft Serve

    APP
    Charm
    < 0.11.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRF
CWE
References

Related vulnerabilities

CVE-2026-30832CRITICAL9.1PL ✓same product

SSRF w Soft Serve — dostęp do wewnętrznych usług przez LFS endpoint

CVE-2026-33353HIGH7.1same product

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.6, an...

CVE-2026-24058HIGH8.1same product

Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authe...

CVE-2023-43809HIGH7.5same product

Soft Serve is a self-hostable Git server for the command line. Prior to version 0.6.2, a security vulnerabilit...

CVE-2026-22253MEDIUM5.4same product

Soft Serve to samodzielnie hostowany serwer Git dla linii poleceń. Przed wersją 0.11.2 błąd autoryzacji w endp...