ZeroHour

CVE-2025-64522

PoC
CVSS 3.1
7.6 high
EPSS
<1%p28
Published
()
Modified
Description

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.

Vendors
charm
Products
soft serve
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.