CVE 8.1 HIGH

Soft Serve has Critical Authentication Bypass_CVE-2026-24058

8.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U

Description

Soft Serve is a self-hostable Git server for the command line. Versions 0.11.2 and below have a critical authentication bypass vulnerability that allows an attacker to impersonate any user (including admin) by "offering" the victim's public key during the SSH handshake before authenticating with their own valid key. This occurs because the user identity is stored in the session context during the "offer" phase and is not cleared if that specific authentication attempt fails. This issue has been fixed in version 0.11.3.

Basic Information

ID CVE-2026-24058
Source GitHub_M
Published Jan 22, 2026 at 22:01
Modified Jan 23, 2026 at 20:14

Affected Product

Vendor charmbracelet
Product soft-serve
Version < 0.11.3
Affected Versions charmbracelet soft-serve < 0.11.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.