CVE-2026-30832Disclosure(charm / soft_serve)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch charm soft_serve systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is blind (the response from a metadata endpoint won't parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at internal targets. This issue has been patched in version 0.11.4.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • soft_serve

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-07); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
soft_serve

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-07: 4Mentions · 2026-03-08: 1Mentions · 2026-03-12: 2Mentions · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-07: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-07: 3Technical Details · 2026-03-08: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-23: 103-0703-0803-1203-23
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-074
Disclosure2General1Patch1
2026-03-081
Disclosure1
2026-03-122
Disclosure2
2026-03-231
Disclosure1
Full discourse8 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-30832 Server-Side Request Forgery in Soft Serve Git Server via Authenticated LFS Import https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30832

    Post summary

    The text references CVE-2026-30832 as an SSRF vulnerability in Soft Serve Git Server via authenticated LFS import, providing only a brief headline with no supporting details about exploits, mitigations, or active usage.

    0101045
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Vulnerability in `soft-serve` allows SSRF via unvalidated LFS endpoint in repo import (CVE-2026-30832). Potential internal network access. #SSRF #GitLFS #infosec https://www.pulsepatch.io/posts/cve-2026-30832-soft-serve-ssrf-vulnerability

    Post summary

    The post discloses an SSRF flaw in soft‑serve’s Git LFS endpoint that could expose internal network resources; it does not confirm exploit code, active attacks, or a fix.

    0000043
    2 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-30832 (CVSS:9.1, CRITICAL) is Analyzed. Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authentic..https://nvd.nist.gov/vuln/detail/CVE-2026-30832 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces a critical vulnerability (CVE-2026-30832) in Soft Serve Git server, noting affected versions and referencing the NVD link, without providing PoC, exploit, mitigation, or active exploitation details.

    0000022
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Soft Serve, Server-Side Request Forgery (SSRF), #CVE-2026-30832 (Critical) https://dailycve.com/soft-serve-server-side-request-forgery-ssrf-cve-2026-30832-critical/

    Post summary

    A new, critical server‑side request forgery vulnerability (CVE‑2026‑30832) has been disclosed, with no indicated exploitation or patch availability yet.

    0000047
    167 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-30832 - Critical Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to interna... https://www.thehackerwire.com/vulnerability/CVE-2026-30832/ https://t.co/TpIADuFHNd

    Post summary

    Soft Serve’s self-hostable Git server has a critical authentication‑related flaw that allows an authenticated SSH user to trigger internal HTTP requests; no evidence of exploitation, PoC, or patch info is provided.

    0000046
    130 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30832 Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTT… https://www.cve.org/CVERecord?id=CVE-2026-30832

    Post summary

    The tweet reveals that CVE-2026‑30832 allows an authenticated SSH user to compel Soft Serve to make outbound HTTP requests, providing limited technical details but no PoC, exploit, patch or active exploitation information.

    00000101
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30832: CRITICAL] Attention Soft Serve users! Prior to version 0.11.4, a vulnerability allowed attackers to force HTTP requests to internal IPs. Update to the latest version for a secure Git server.#cve,CVE-2026-30832,#cybersecurity https://cvefind.com/CVE-2026-30832

    Post summary

    The message announces that CVE-2026-30832, a critical vulnerability in Soft Serve, allows attackers to force HTTP requests to internal IPs. Users are urged to update to version 0.11.4 or later to remediate the issue.

    0000064
    599 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30832: Soft Serve: SSRF via unvalidated... Blind SSRF escalates to full internal network read via malicious LFS server returning crafted download URLs pointing at... https://zerodaysignal.com/vulnerability/CVE-2026-30832 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-30832, a blind SSRF vulnerability in Soft Serve that can be leveraged for full internal network read, and provides a link likely containing technical details and possible PoC. No active exploitation, patch, or false‑positive information is discussed.

    0000082
    140 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcharmsoft_serve-go-

Explore more