CVE-2026-86117
- EPSS 0.42%
- Veröffentlicht 05.09.2026 10:16:42
- Zuletzt bearbeitet 10.09.2026 16:18:01
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Attackers ca...
CVE-2026-34037
- EPSS 0.3%
- Veröffentlicht 07.07.2026 03:21:52
- Zuletzt bearbeitet 07.07.2026 15:16:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but resolves destination resources wit...
CVE-2026-34048
- EPSS 0.58%
- Veröffentlicht 07.07.2026 03:19:42
- Zuletzt bearbeitet 07.07.2026 15:16:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privi...
CVE-2026-34057
- EPSS 0.35%
- Veröffentlicht 07.07.2026 03:17:37
- Zuletzt bearbeitet 07.07.2026 14:16:30
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows client-controlled container and serv...
CVE-2026-42147
- EPSS 0.26%
- Veröffentlicht 07.07.2026 03:13:50
- Zuletzt bearbeitet 07.07.2026 15:16:46
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side request to the configured endp...
CVE-2026-34152
- EPSS 0.37%
- Veröffentlicht 07.07.2026 03:11:14
- Zuletzt bearbeitet 09.07.2026 16:16:39
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH heredoc transport that preserv...
CVE-2026-34149
- EPSS 0.22%
- Veröffentlicht 07.07.2026 03:09:33
- Zuletzt bearbeitet 07.07.2026 15:16:44
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection exclusion names into backup shell ...
CVE-2026-34034
- EPSS 0.4%
- Veröffentlicht 07.07.2026 03:06:31
- Zuletzt bearbeitet 07.07.2026 13:22:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing an authenticated user with acces...
CVE-2026-42145
- EPSS 0.25%
- Veröffentlicht 07.07.2026 03:03:58
- Zuletzt bearbeitet 09.07.2026 16:16:41
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file...
CVE-2026-34047
- EPSS 0.45%
- Veröffentlicht 07.07.2026 02:54:59
- Zuletzt bearbeitet 07.07.2026 15:16:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware, allowing an authenticated user to ...