CVE-2026-42153
- EPSS 0.36%
- Veröffentlicht 06.07.2026 21:30:44
- Zuletzt bearbeitet 07.07.2026 14:16:30
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings (postgres_user and postgres_db) in shell...
CVE-2026-34049
- EPSS 0.2%
- Veröffentlicht 06.07.2026 21:22:46
- Zuletzt bearbeitet 07.07.2026 13:22:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.451 through 4.0.0-beta.470, database backup handling for MongoDB collection names did not fully validate shell metacharacters, allowin...
CVE-2026-42204
- EPSS 0.36%
- Veröffentlicht 06.07.2026 21:17:16
- Zuletzt bearbeitet 07.07.2026 15:16:46
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom Docker Compose build, start, and p...
CVE-2026-42148
- EPSS 0.12%
- Veröffentlicht 06.07.2026 21:14:31
- Zuletzt bearbeitet 07.07.2026 13:22:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build command using the dev_helper_version...
CVE-2026-41899
- EPSS 0.3%
- Veröffentlicht 06.07.2026 21:10:40
- Zuletzt bearbeitet 07.07.2026 15:16:45
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forward...
CVE-2026-34050
- EPSS 0.21%
- Veröffentlicht 06.07.2026 21:08:08
- Zuletzt bearbeitet 07.07.2026 15:16:44
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Settings/Updates Livewire component does not check isInstanceAdmin in its mount method, allowing non-admin users to acces...
CVE-2026-32718
- EPSS 0.21%
- Veröffentlicht 06.07.2026 21:04:59
- Zuletzt bearbeitet 07.07.2026 15:16:43
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, mutating API validation endpoints are guarded by read ability, allowing read-scoped API tokens to perform state-changing oper...
CVE-2026-34038
- EPSS 1.75%
- Veröffentlicht 06.07.2026 20:48:23
- Zuletzt bearbeitet 07.07.2026 13:22:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote command injection vulnerability in application deployment handling allows users with application writ...
CVE-2026-27957
- EPSS 0.66%
- Veröffentlicht 30.06.2026 14:39:06
- Zuletzt bearbeitet 30.06.2026 19:58:59
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command injection vulnerability in the CA Certificate management feature allows any authenticated user to ex...
- EPSS 0.21%
- Veröffentlicht 30.06.2026 14:32:25
- Zuletzt bearbeitet 01.07.2026 16:16:46
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any tea...