CVE-2025-64420
- EPSS 0.5%
- Veröffentlicht 05.01.2026 19:20:24
- Zuletzt bearbeitet 12.01.2026 14:31:59
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify insta...
CVE-2025-64419
- EPSS 0.63%
- Veröffentlicht 05.01.2026 19:16:44
- Zuletzt bearbeitet 12.01.2026 14:38:09
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an appli...
CVE-2025-59955
- EPSS 0.26%
- Veröffentlicht 05.01.2026 17:46:56
- Zuletzt bearbeitet 12.01.2026 14:48:13
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/...
- EPSS 0.48%
- Veröffentlicht 05.01.2026 17:44:41
- Zuletzt bearbeitet 12.01.2026 15:08:33
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflo...
CVE-2025-59157
- EPSS 1.83%
- Veröffentlicht 05.01.2026 17:41:29
- Zuletzt bearbeitet 12.01.2026 15:02:21
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not properly san...
CVE-2025-59156
- EPSS 0.97%
- Veröffentlicht 05.01.2026 17:39:42
- Zuletzt bearbeitet 12.01.2026 15:03:44
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deployment workflow. This flaw allows a...
CVE-2025-66213
- EPSS 3.17%
- Veröffentlicht 23.12.2025 22:15:52
- Zuletzt bearbeitet 17.03.2026 17:16:14
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the File Storage Directory Mount Path functionality allows users ...
CVE-2025-66212
- EPSS 3.17%
- Veröffentlicht 23.12.2025 22:15:52
- Zuletzt bearbeitet 17.03.2026 17:16:14
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic Proxy Configuration Filename handling allows users wi...
CVE-2025-66211
- EPSS 2.78%
- Veröffentlicht 23.12.2025 22:15:52
- Zuletzt bearbeitet 17.03.2026 17:16:14
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in PostgreSQL Init Script Filename handling allows users with applic...
CVE-2025-66210
- EPSS 2.78%
- Veröffentlicht 23.12.2025 21:49:44
- Zuletzt bearbeitet 17.03.2026 17:16:14
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Import functionality allows users with application/s...