<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 04:05:09 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-00070</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-00070</link>
      <description>bdu:2026-00070</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-00070</guid>
    </item>
    <item>
      <title>EUVD-2026-260637</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260637</link>
      <description>EUVD-2026-260637</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260637</guid>
    </item>
    <item>
      <title>fkie_cve-2025-64522</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-64522</link>
      <description>&lt;p&gt;Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-64522</guid>
    </item>
    <item>
      <title>GHSA-vwq2-jx9q-9h9f — Soft Serve is vulnerable to SSRF through its Webhooks</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-vwq2-jx9q-9h9f</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/charmbracelet/soft-serve&lt;/p&gt;
&lt;p&gt;SUMMARY&lt;/p&gt;
&lt;p&gt;We have identified and verified an SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints.&lt;/p&gt;
&lt;p&gt;AFFECTED COMPONENTS (VERIFIED)&lt;/p&gt;
&lt;p&gt;1. Webhook Creation (pkg/ssh/cmd/webhooks.go:125)
2. Backend CreateWebhook (pkg/backend/webhooks.go:17)
3. Backend UpdateWebhook (pkg/backend/webhooks.go:122)
4. Webhook Delivery (pkg/webhook/webhook.go:97)&lt;/p&gt;
&lt;p&gt;IMPACT&lt;/p&gt;
&lt;p&gt;This vulnerability allows repository administrators to perform SSRF attacks, potentially enabling:&lt;/p&gt;
&lt;p&gt;a) Cloud Metadata Theft - Access AWS/Azure/GCP credentials via 169.254.169.254
b) Internal Network Access - Target localhost and private networks (10.x, 192.168.x, 172.16.x)
c) Port Scanning - Enumerate internal services via response codes and timing
d) Data Exfiltration - Full HTTP responses stored in webhook delivery logs
e) Internal API Access - Call internal admin panels and Kubernetes endpoints&lt;/p&gt;
&lt;p&gt;PROOF OF CONCEPT&lt;/p&gt;
&lt;p&gt;Simple example demonstrating localhost access:&lt;/p&gt;
&lt;p&gt;```sh
ssh localhost webhook create my-repo http://127.0.0.1:8080/internal \
    --events push --active
```&lt;/p&gt;
&lt;p&gt;then push to trigger.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/charmbracelet/soft-serve&lt;/p&gt;
&lt;p&gt;SUMMARY&lt;/p&gt;
&lt;p&gt;We have identified and verified an SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints.&lt;/p&gt;
&lt;p&gt;AFFECTED COMPONENTS (VERIFIED)&lt;/p&gt;
&lt;p&gt;1. Webhook Creation (pkg/ssh/cmd/webhooks.go:125)
2. Backend CreateWebhook (pkg/backend/webhooks.go:17)
3. Backend UpdateWebhook (pkg/backend/webhooks.go:122)
4. Webhook Delivery (pkg/webhook/webhook.go:97)&lt;/p&gt;
&lt;p&gt;IMPACT&lt;/p&gt;
&lt;p&gt;This vulnerability allows repository administrators to perform SSRF attacks, potentially enabling:&lt;/p&gt;
&lt;p&gt;a) Cloud Metadata Theft - Access AWS/Azure/GCP credentials via 169.254.169.254
b) Internal Network Access - Target localhost and private networks (10.x, 192.168.x, 172.16.x)
c) Port Scanning - Enumerate internal services via response codes and timing
d) Data Exfiltration - Full HTTP responses stored in webhook delivery logs
e) Internal API Access - Call internal admin panels and Kubernetes endpoints&lt;/p&gt;
&lt;p&gt;PROOF OF CONCEPT&lt;/p&gt;
&lt;p&gt;Simple example demonstrating localhost access:&lt;/p&gt;
&lt;p&gt;```sh
ssh localhost webhook create my-repo http://127.0.0.1:8080/internal \
    --events push --active
```&lt;/p&gt;
&lt;p&gt;then push to trigger.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-vwq2-jx9q-9h9f</guid>
    </item>
  </channel>
</rss>
