Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22253

Опубликовано: 08 янв. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2.

EPSS

Процентиль: 12%
0.0004
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 5.4
github
12 дней назад

Soft Serve is missing an authorization check in LFS lock deletion

EPSS

Процентиль: 12%
0.0004
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-863