cbcvebase.

Coollabsio Coolify vulnerabilities

75 known vulnerabilities affecting coollabsio/coolify.

Total CVEs
75
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH41MEDIUM20LOW6

Vulnerabilities

Page 4 of 4
CVE-2026-34198P4MEDIUMCVSS 5.3fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34198 [MEDIUM] CWE-346 CVE-2026-34198: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), accepting X-Forwarded-Host from any source. The TrustHosts middleware, intended to prevent host header attacks, has a circular caching dependency that prevents it
nvd
CVE-2026-27881P4MEDIUMCVSS 5.0fixed in 4.0.0-beta.4642026-06-30
CVE-2026-27881 [MEDIUM] CWE-639 CVE-2026-27881: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments/{uuid}` in DeployController.php retrieves deployment details without validating that the deployment belongs to the authenticated user's team. Any authenticated API user can read deployment records from
nvd
CVE-2026-42147P4MEDIUMCVSS 4.9fixed in 4.0.0-beta.4742026-07-07
CVE-2026-42147 [MEDIUM] CWE-918 CVE-2026-42147: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side request to the configured endpoint, allowing an authenticated user with storage management permissions to make Coolify request inter
nvd
CVE-2025-22607P4MEDIUMCVSS 5.5fixed in 4.0.0-beta.3612025-01-24
CVE-2025-22607 [MEDIUM] CWE-200 CVE-2025-22607: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.361, the missing authorization allows any authenticated user to fetch the details page for any GitHub / GitLab configuration on a Coolify instance by only knowing the UUID of the model. This exposes the "client id", "client
nvd
CVE-2026-27882P4MEDIUMCVSS 4.8fixed in 4.0.0-beta.4612026-06-30
CVE-2026-27882 [MEDIUM] CWE-208 CVE-2026-27882: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation is vulnerable to timing attacks, which could allow an attacker to gradually discove
nvd
CVE-2025-24025P4MEDIUMCVSS 6.1fixed in 4.0.0-beta.3612025-01-24
CVE-2025-24025 [MEDIUM] CWE-116 CVE-2025-24025: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.380, the tags page allows users to search for tags. If the search does not return any results, the query gets reflected on the error modal, which leads to cross-site scripting. Version 4.0.0-beta.380 fixes the issue.
nvd
CVE-2026-34170P4MEDIUMCVSS 4.3fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34170 [MEDIUM] CWE-918 CVE-2026-34170: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base URL for server-side HTTP requests without allowlisting or private IP blocking, allowing an authenticated user to configure a GitHub App source that causes Coolify to request inter
nvd
CVE-2026-27956P4MEDIUMCVSS 4.3fixed in 4.0.0-beta.4642026-06-30
CVE-2026-27956 [MEDIUM] CWE-639 CVE-2026-27956: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/servers/{server_uuid}/domains?uuid={app_uuid}` bypasses team scoping when the optional uuid query parameter is provided. Any authenticated API user can enumerate domain names (FQDNs) of applications belonging to ot
nvd
CVE-2025-64422P4MEDIUMCVSS 4.3v>= 4.0.0-beta.4342026-01-05
CVE-2025-64422 [MEDIUM] CWE-770 CVE-2025-64422: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimited credential stuffing and brute-force attempts agains
nvd
CVE-2026-42148P4LOWCVSS 3.8fixed in 4.0.0-beta.4742026-07-06
CVE-2026-42148 [LOW] CWE-78 CVE-2026-42148: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version field without shell escaping, allowing an attacker who can set the helper version and trigger the helper
nvd
CVE-2026-34149P4LOWCVSS 3.3fixed in 4.0.0-beta.4712026-07-07
CVE-2026-34149 [LOW] CWE-78 CVE-2026-34149: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection exclusion names into backup shell commands without adequate escaping, allowing an authenticated user with database management permissions to
nvd
CVE-2026-42145P4LOWCVSS 3.1fixed in 4.0.0-beta.4742026-07-07
CVE-2026-42145 [LOW] CWE-434 CVE-2026-42145: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that cou
nvd
CVE-2026-42201P4LOWCVSS 3.3fixed in 4.0.0-beta.4742026-07-07
CVE-2026-42201 [LOW] CWE-78 CVE-2026-42201: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password, clickhouse_admin_user, clickhouse_admin_password, postgres_user, mysql_user) are validated only as 'string' at the API layer, with zero shell-safety ch
nvd
CVE-2026-34049P4LOWCVSS 3.3v>= 4.0.0-beta.451, < 4.0.0-beta.4712026-07-06
CVE-2026-34049 [LOW] CWE-78 CVE-2026-34049: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowing a highly privileged attacker who can configure backup inputs to inject commands. This issue is fixed in
nvd
CVE-2026-42172P4LOWCVSS 3.1fixed in 4.0.0-beta.4742026-07-07
CVE-2026-42172 [LOW] CWE-613 CVE-2026-42172: Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked token to retain access indefinitely until manually revoked. This issue is fixed in version 4.0.0-beta.474.
nvd
Coollabsio Coolify vulnerabilities | cvebase