- EPSS 0.21%
- Veröffentlicht 30.06.2026 14:32:25
- Zuletzt bearbeitet 01.07.2026 16:16:46
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deployments/{uuid}` endpoint allows any authenticated user to access deployment details belonging to any tea...
- EPSS 0.16%
- Veröffentlicht 30.06.2026 14:28:38
- Zuletzt bearbeitet 30.06.2026 20:17:29
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments/{uuid}` in DeployController.php retrieves deployment details without validating that the deployment ...
CVE-2026-27882
- EPSS 0.15%
- Veröffentlicht 30.06.2026 14:26:44
- Zuletzt bearbeitet 30.06.2026 19:58:59
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.461, the GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. T...
CVE-2026-34592
- EPSS 0.21%
- Veröffentlicht 29.06.2026 21:47:23
- Zuletzt bearbeitet 30.06.2026 14:14:35
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and project lookups are not scoped to the current team, allowing any authenticated user to access servers and ...
CVE-2026-34594
- EPSS 1.09%
- Veröffentlicht 29.06.2026 20:21:59
- Zuletzt bearbeitet 01.07.2026 15:17:07
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command injection vulnerability in the Destination Network Management functionality allows users with destin...
CVE-2026-57498
- EPSS 0.25%
- Veröffentlicht 29.06.2026 20:17:40
- Zuletzt bearbeitet 30.06.2026 17:16:23
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($teamId) before any operation. Howe...
CVE-2025-64425
- EPSS 0.36%
- Veröffentlicht 05.01.2026 20:49:10
- Zuletzt bearbeitet 07.10.2026 10:10:00
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, an attacker can initiate a password reset for a victim, and modify the host header of the req...
CVE-2025-64424
- EPSS 1.97%
- Veröffentlicht 05.01.2026 20:45:09
- Zuletzt bearbeitet 07.10.2026 10:10:00
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a resource, allowi...
CVE-2025-64423
- EPSS 0.3%
- Veröffentlicht 05.01.2026 20:41:37
- Zuletzt bearbeitet 07.10.2026 10:10:00
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a low privileged user (member) can see and use invitation links sent to an administrator. Whe...
CVE-2025-64422
- EPSS 0.26%
- Veröffentlicht 05.01.2026 20:29:34
- Zuletzt bearbeitet 07.10.2026 10:10:00
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating ...