CVE-2026-34037
- EPSS 0.3%
- Veröffentlicht 07.07.2026 03:21:52
- Zuletzt bearbeitet 07.07.2026 15:16:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources wit...
CVE-2026-34048
- EPSS 0.58%
- Veröffentlicht 07.07.2026 03:19:42
- Zuletzt bearbeitet 07.07.2026 15:16:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privi...
CVE-2026-34057
- EPSS 0.35%
- Veröffentlicht 07.07.2026 03:17:37
- Zuletzt bearbeitet 07.07.2026 14:16:30
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows client-controlled container and serv...
CVE-2026-42147
- EPSS 0.26%
- Veröffentlicht 07.07.2026 03:13:50
- Zuletzt bearbeitet 07.07.2026 15:16:46
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side request to the configured endp...
CVE-2026-34152
- EPSS 0.37%
- Veröffentlicht 07.07.2026 03:11:14
- Zuletzt bearbeitet 09.07.2026 16:16:39
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that preserv...
CVE-2026-34149
- EPSS 0.22%
- Veröffentlicht 07.07.2026 03:09:33
- Zuletzt bearbeitet 07.07.2026 15:16:44
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection exclusion names into backup shell ...
CVE-2026-34034
- EPSS 0.4%
- Veröffentlicht 07.07.2026 03:06:31
- Zuletzt bearbeitet 07.07.2026 13:22:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with acces...
CVE-2026-42145
- EPSS 0.25%
- Veröffentlicht 07.07.2026 03:03:58
- Zuletzt bearbeitet 09.07.2026 16:16:41
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file...
CVE-2026-34047
- EPSS 0.45%
- Veröffentlicht 07.07.2026 02:54:59
- Zuletzt bearbeitet 07.07.2026 15:16:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to ...
CVE-2026-42200
- EPSS 0.54%
- Veröffentlicht 07.07.2026 02:48:04
- Zuletzt bearbeitet 07.07.2026 13:22:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in app/Actions/Database/StartPostgresql.php) filename handli...