
Today I’m publishing CVE-2026-33353, a high severity (7.1) auth bypass vulnerability in Soft Serve that lets any authenticated user clone other users’ private repositories from the server. Upgrade to 0.11.6 to patch.
Post summary
The author publicly announces CVE-2026-33353, an auth‑bypass vulnerability in Soft Serve with a severity of 7.1, and recommends upgrading to version 0.11.6 to remediate it.


