VYPR

Coolify

by Coollabs

CVEs (28)

  • CVE-2025-64422MedJan 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header.…

  • CVE-2025-64419CriJan 5, 2026
    risk 0.00cvss 9.6epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user creates an application from an attacker…

  • CVE-2025-66213HigDec 23, 2025
    risk 0.00cvss 8.8epss 0.03

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the File Storage Directory Mount Path functionality allows users with application/service…

  • CVE-2025-66212HigDec 23, 2025
    risk 0.00cvss 8.8epss 0.03

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Dynamic Proxy Configuration Filename handling allows users with application/service…

  • CVE-2025-66211HigDec 23, 2025
    risk 0.00cvss 8.8epss 0.03

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in PostgreSQL Init Script Filename handling allows users with application/service management…

  • CVE-2025-66210HigDec 23, 2025
    risk 0.00cvss 8.8epss 0.03

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Import functionality allows users with application/service management permissions…

  • CVE-2025-66209CriDec 23, 2025
    risk 0.00cvss 9.9epss 0.04

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.451, an authenticated command injection vulnerability in the Database Backup functionality allows users with application/service management permissions…

  • CVE-2025-22605HigJan 24, 2025
    risk 0.00cvss 7.8epss 0.01

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Starting in version 4.0.0-beta.18 and prior to 4.0.0-beta.253, a vulnerability in the execution of commands on remote servers allows an authenticated user to execute arbitrary…

Page 2 of 2