CVE-2025-64425
- EPSS 0.05%
- Veröffentlicht 05.01.2026 20:49:10
- Zuletzt bearbeitet 12.01.2026 18:36:12
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the req...
CVE-2025-64424
- EPSS 0.47%
- Veröffentlicht 05.01.2026 20:45:09
- Zuletzt bearbeitet 12.01.2026 18:37:11
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowi...
CVE-2025-64423
- EPSS 0.05%
- Veröffentlicht 05.01.2026 20:41:37
- Zuletzt bearbeitet 09.01.2026 16:10:47
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. Whe...
CVE-2025-64422
- EPSS 0.05%
- Veröffentlicht 05.01.2026 20:29:34
- Zuletzt bearbeitet 12.01.2026 14:23:36
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating ...
- EPSS 0.04%
- Veröffentlicht 05.01.2026 19:42:46
- Zuletzt bearbeitet 12.01.2026 14:26:45
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can invite a high privileged user. At first, the application w...
CVE-2025-64420
- EPSS 0.05%
- Veröffentlicht 05.01.2026 19:20:24
- Zuletzt bearbeitet 12.01.2026 14:31:59
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify insta...
CVE-2025-64419
- EPSS 0.09%
- Veröffentlicht 05.01.2026 19:16:44
- Zuletzt bearbeitet 12.01.2026 14:38:09
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an appli...
CVE-2025-59955
- EPSS 0.04%
- Veröffentlicht 05.01.2026 17:46:56
- Zuletzt bearbeitet 12.01.2026 14:48:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/...
- EPSS 0.05%
- Veröffentlicht 05.01.2026 17:44:41
- Zuletzt bearbeitet 12.01.2026 15:08:33
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflo...
CVE-2025-59157
- EPSS 0.26%
- Veröffentlicht 05.01.2026 17:41:29
- Zuletzt bearbeitet 12.01.2026 15:02:21
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly san...