CVE-2026-22253
Last modified
CVE-2026-22253 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Charm | Soft Serve | < 0.11.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-22253?
How severe is CVE-2026-22253?
How do I fix CVE-2026-22253?
Are you affected by CVE-2026-22253?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
