CVE-2025-64522

Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:charm:soft_serve:*:*:*:*:*:go:*:*

History

No history.

Information

Published : 2025-11-10 23:15

Updated : 2025-12-31 17:54


NVD link : CVE-2025-64522

Mitre link : CVE-2025-64522

CVE.ORG link : CVE-2025-64522


JSON object : View

Products Affected

charm

  • soft_serve
CWE
CWE-918

Server-Side Request Forgery (SSRF)