Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Soft Serve versions 0.7.1 through 0.11.6 have an authorization bypass vulnerability where Git LFS lock queries are not properly scoped by repository. This allows authenticated users with write access to any repository to read lock metadata from repositories they should not access, including private ones. Attackers can enumerate lock IDs globally to obtain locked file paths, usernames, and lock timestamps from unauthorized repositories. Join the discussion | CVE Database V5 | 09/15/2026, 01:20:34 UTC Added: 09/15/2026, 02:02:16 UTC |
0 CVE-2026-33353 is a high-severity authorization vulnerability in charmbracelet's Soft Serve Git server versions 0.6.0 up to but not including 0.11.6. The flaw allows any authenticated SSH user to clone local Git repositories owned by other users, including private repositories, by exploiting an improper authorization check during repository import. This leads to unauthorized exposure of sensitive source code and intellectual property. The vulnerability requires authenticated SSH access but no additional user interaction or elevated privileges. It has been patched in version 0.11. Join the discussion | CVE Database V5 | 03/24/2026, 19:39:38 UTC Added: 03/24/2026, 20:03:02 UTC |
0 Soft Serve is a self-hostable Git server for the command line. From version 0.6.0 to before version 0.11.4, an authenticated SSH user can force the server to make HTTP requests to internal/private IP addresses by running repo import with a crafted --lfs-endpoint URL. The initial batch request is blind (the response from a metadata endpoint won't parse as valid LFS JSON), but an attacker hosting a fake LFS server can chain this into full read access to internal services by returning download URLs that point at internal targets. This issue has been patched in version 0.11.4. Join the discussion | CVE Database V5 | 03/07/2026, 15:57:39 UTC Added: 03/07/2026, 16:16:11 UTC |
0 CVE-2026-24058 is a critical authentication bypass vulnerability in charmbracelet soft-serve versions 0.11.2 and below. The flaw allows an attacker to impersonate any user, including administrators, by exploiting the SSH handshake process. Specifically, the vulnerability arises because the victim's public key is 'offered' during the SSH handshake and the user identity is stored in the session context prematurely. If the attacker fails to authenticate with the victim's key but then authenticates with their own valid key, the session context is not cleared, allowing the attacker to assume the victim's identity. This vulnerability has a high CVSS 4.0 score of 8.1 and does not require authentication or user interaction to exploit. The issue was fixed in version 0. Join the discussion | CVE Database V5 | 01/22/2026, 22:01:22 UTC Added: 01/22/2026, 22:20:56 UTC |
Soft Serve is a self-hostable Git server for the command line. Prior to version 0.11.2, an authorization bypass in the LFS lock deletion endpoint allows any authenticated user with repository write access to delete locks owned by other users by setting the force flag. The vulnerable code path processes force deletions before retrieving user context, bypassing ownership validation entirely. This issue has been patched in version 0.11.2. Join the discussion | CVE Database V5 | 01/08/2026, 18:39:57 UTC Added: 01/08/2026, 18:54:14 UTC |
0 Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where webhook URLs are not validated, allowing repository administrators to create webhooks targeting internal services, private networks, and cloud metadata endpoints. Version 0.11.1 fixes the vulnerability. Join the discussion | CVE Database V5 | 11/10/2025, 22:11:18 UTC Added: 11/10/2025, 22:28:47 UTC |
0 Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places where the user can insert data (e.g.names) and ANSI escape sequences are not being removed, which can then be used, for example, to show fake alerts. In the same token, git messages, when printed, are also not being sanitized. This issue is fixed in version 0.10.0. Join the discussion | CVE Database V5 | 11/08/2025, 01:19:01 UTC Added: 11/08/2025, 01:38:18 UTC |
Showing 1 to 7 of 7 results