Coollabs
Coollabs Coolify: vulnerabilidades y CVE
Coollabs Coolify tiene 78 vulnerabilidades publicadas, 66 de ellas en los últimos 12 meses. 19 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE78
Últimos 12 meses66
Críticas19
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100746 | Media (5.5) | 0.50% | — | 27 sept 2026 | A vulnerability was found in coollabsio Coolify up to 4.1.0. This affects the function Github::redirect of the file /webhooks/source/github/redirect of the component GitHub App Setup Handler. The manipulation of the… |
| CVE-2026-100744 | Media (5.5) | 0.45% | — | 27 sept 2026 | A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Http/Middleware/CanUpdateResource.php of the component Route-Level Middleware. Executing a… |
| CVE-2026-86117 | Crítica (9.2) | 0.67% | — | 5 sept 2026 | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding… |
| CVE-2026-84694 | Alta (8.7) | 0.84% | — | 2 sept 2026 | Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable… |
| CVE-2026-15507 | Baja (2.1) | 0.35% | — | 12 jul 2026 | A vulnerability was detected in coollabsio Coolify up to 4.1.1. The impacted element is an unknown function of the file /app/Policies/ of the component Policy Handler. Performing a manipulation results in missing… |
| CVE-2026-59734 | Alta (8.8) | 0.81% | — | 9 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, Coolify's app/Jobs/ApplicationDeploymentJob.php generate_healthcheck_commands() function… |
| CVE-2026-42201 | Baja (3.3) | 0.31% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, database credential fields (redis_password, keydb_password, dragonfly_password,… |
| CVE-2026-34158 | Alta (8.8) | 0.65% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() helper wraps user-controlled commands in single quotes without escaping… |
| CVE-2026-42200 | Alta (8.8) | 0.89% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL initialization script (generate_init_scripts() method in… |
| CVE-2026-42172 | Baja (3.1) | 0.30% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked token to retain access indefinitely until… |
| CVE-2026-42147 | Media (4.9) | 0.44% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, S3 storage endpoint validation only checks URL format and testConnection() sends a server-side… |
| CVE-2026-42145 | Baja (3.1) | 0.39% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup… |
| CVE-2026-42143 | Alta (8.8) | 0.78% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, user-controlled persistent volume names are interpolated into shell commands executed on… |
| CVE-2026-34198 | Media (5.3) | 0.20% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), accepting X-Forwarded-Host… |
| CVE-2026-34171 | Alta (8) | 0.20% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GET /invitations/{uuid} endpoint can perform a state-changing password reset using an… |
| CVE-2026-34170 | Media (4.3) | 0.27% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp api_url field is used as the base URL for server-side HTTP requests without… |
| CVE-2026-34168 | Alta (8.8) | 0.78% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the LocalPersistentVolume.name field is interpolated directly into docker volume shell… |
| CVE-2026-34152 | Alta (8.8) | 0.65% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, pre-deployment and post-deployment commands are single-quote escaped but then sent through SSH… |
| CVE-2026-34149 | Baja (3.3) | 0.36% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, DatabaseBackupJob interpolates user-controlled database credentials and MongoDB collection… |
| CVE-2026-34058 | Alta (8.8) | 0.65% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the Livewire component Server\Resources exposes public methods (startUnmanaged, stopUnmanaged,… |
| CVE-2026-34057 | Alta (8.8) | 0.63% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the database import Livewire component (app/Livewire/Project/Database/Import.php) allows… |
| CVE-2026-34048 | Crítica (9.9) | 0.80% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal… |
| CVE-2026-34047 | Crítica (9.9) | 0.71% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket bootstrap routes did not enforce the expected authorization middleware,… |
| CVE-2026-34044 | Alta (7.7) | 0.40% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the Logs::mount() component looks up resources by UUID without scoping the lookup to the… |
| CVE-2026-34037 | Crítica (9.9) | 0.44% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperations.php authorizes the source resource but… |
| CVE-2026-34035 | Alta (8.8) | 0.63% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, log drain secret and environment values were interpolated into shell commands without… |
| CVE-2026-34034 | Alta (8.8) | 0.78% | — | 7 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.466, the sentinel_token setting is used in shell commands without sufficient validation, allowing… |
| CVE-2026-42204 | Alta (8.8) | 0.65% | — | 6 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. From 4.0.0-beta.471 through 4.0.0-beta.473, a regression in SHELL_SAFE_COMMAND_PATTERN allowed ampersands in custom… |
| CVE-2026-42153 | Alta (8.8) | 0.65% | — | 6 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, PostgreSQL healthcheck command generation used attacker-controlled database settings… |
| CVE-2026-42148 | Baja (3.8) | 0.16% | — | 6 jul 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the buildHelperImage method in app/Livewire/Settings/Index.php constructs a Docker build… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.