3.1
CVE-2026-42145
- EPSS 0.25%
- Veröffentlicht 07.07.2026 03:03:58
- Zuletzt bearbeitet 09.07.2026 16:16:41
- CVE-Watchlists
- Unerledigt
Coolify: File Upload Without Type or Size Validation in Database Backup Restore
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. This issue is fixed in version 4.0.0-beta.474.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellercoollabsio
≫
Produkt
coolify
Version
< 4.0.0-beta.474
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.162 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474
https://github.com/coollabsio/coolify/pull/9667
https://github.com/coollabsio/coolify/commit/e6a6446daeace2999fb77888a611a3271812911f
https://github.com/coollabsio/coolify/security/advisories/GHSA-66gv-g2w9-6wxp