« Volver al listado

Coollabs

Coollabs Coolify: vulnerabilidades y CVE

Coollabs Coolify tiene 78 vulnerabilidades publicadas, 66 de ellas en los últimos 12 meses. 19 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE78
Últimos 12 meses66
Críticas19
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-100746Media (5.5)0.50%—27 sept 2026
A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the…
CVE-2026-100744Media (5.5)0.45%—27 sept 2026
A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a…
CVE-2026-86117Crítica (9.2)0.67%—5 sept 2026
Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding…
CVE-2026-84694Alta (8.7)0.84%—2 sept 2026
Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable…
CVE-2026-15507Baja (2.1)0.35%—12 jul 2026
A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing…
CVE-2026-59734Alta (8.8)0.81%—9 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function…
CVE-2026-42201Baja (3.3)0.31%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password,…
CVE-2026-34158Alta (8.8)0.65%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping…
CVE-2026-42200Alta (8.8)0.89%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in…
CVE-2026-42172Baja (3.1)0.30%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked token to retain access indefinitely until…
CVE-2026-42147Media (4.9)0.44%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side…
CVE-2026-42145Baja (3.1)0.39%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup…
CVE-2026-42143Alta (8.8)0.78%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on…
CVE-2026-34198Media (5.3)0.20%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), accepting X-Forwarded-Host…
CVE-2026-34171Alta (8)0.20%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an…
CVE-2026-34170Media (4.3)0.27%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base URL for server-side HTTP requests without…
CVE-2026-34168Alta (8.8)0.78%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell…
CVE-2026-34152Alta (8.8)0.65%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH…
CVE-2026-34149Baja (3.3)0.36%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection…
CVE-2026-34058Alta (8.8)0.65%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Livewire component Server\Resources exposes public methods (startUnmanaged, stopUnmanaged,…
CVE-2026-34057Alta (8.8)0.63%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows…
CVE-2026-34048Crítica (9.9)0.80%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal…
CVE-2026-34047Crítica (9.9)0.71%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware,…
CVE-2026-34044Alta (7.7)0.40%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() component looks up resources by UUID without scoping the lookup to the…
CVE-2026-34037Crítica (9.9)0.44%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but…
CVE-2026-34035Alta (8.8)0.63%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without…
CVE-2026-34034Alta (8.8)0.78%—7 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing…
CVE-2026-42204Alta (8.8)0.65%—6 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom…
CVE-2026-42153Alta (8.8)0.65%—6 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings…
CVE-2026-42148Baja (3.8)0.16%—6 jul 2026
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts3
  2. T1190 Exploit Public-Facing Application3
  3. T1059 Command and Scripting Interpreter1
  4. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.