- EPSS 0.16%
- Veröffentlicht 30.06.2026 14:28:38
- Zuletzt bearbeitet 30.06.2026 20:17:29
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments/{uuid}` in DeployController.php retrieves deployment details without validating that the deployment ...
CVE-2026-27882
- EPSS 0.15%
- Veröffentlicht 30.06.2026 14:26:44
- Zuletzt bearbeitet 30.06.2026 19:58:59
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. T...
CVE-2026-34592
- EPSS 0.21%
- Veröffentlicht 29.06.2026 21:47:23
- Zuletzt bearbeitet 30.06.2026 14:14:35
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and project lookups are not scoped to the current team, allowing any authenticated user to access servers and ...
CVE-2026-34594
- EPSS 1.09%
- Veröffentlicht 29.06.2026 20:21:59
- Zuletzt bearbeitet 01.07.2026 15:17:07
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality allows users with destin...
CVE-2026-57498
- EPSS 0.25%
- Veröffentlicht 29.06.2026 20:17:40
- Zuletzt bearbeitet 30.06.2026 17:16:23
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. Howe...
CVE-2025-64425
- EPSS 0.36%
- Veröffentlicht 05.01.2026 20:49:10
- Zuletzt bearbeitet 12.01.2026 18:36:12
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the req...
CVE-2025-64424
- EPSS 1.97%
- Veröffentlicht 05.01.2026 20:45:09
- Zuletzt bearbeitet 12.01.2026 18:37:11
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowi...
CVE-2025-64423
- EPSS 0.3%
- Veröffentlicht 05.01.2026 20:41:37
- Zuletzt bearbeitet 09.01.2026 16:10:47
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. Whe...
CVE-2025-64422
- EPSS 0.26%
- Veröffentlicht 05.01.2026 20:29:34
- Zuletzt bearbeitet 12.01.2026 14:23:36
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating ...
- EPSS 0.26%
- Veröffentlicht 05.01.2026 19:42:46
- Zuletzt bearbeitet 12.01.2026 14:26:45
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can invite a high privileged user. At first, the application w...