Coolify
Coollabs · 28 CVEs
Coolify has host header injection in forgot password
Jan 5, 2026
Colify has command injection vulnerability in project git source
Jan 5, 2026
Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links
Jan 5, 2026
Rate-limit bypass on login via X-Forwarded-Host header
Jan 5, 2026
Coolify has a privilege escalation - low privileged user can invite themselves as an admin user
Jan 5, 2026
Coolify members can see private key of root user
Jan 5, 2026
Coolify vulnerable to command injection via docker-compose.yaml parameters
Jan 5, 2026
Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint
Jan 5, 2026
Coolify has Stored XSS in Project Name
Jan 5, 2026
Coolify has Git Repository RCE
Jan 5, 2026
Coolify has Docker Compose Injection issue
Jan 5, 2026
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount Path
Dec 23, 2025
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration Filename
Dec 23, 2025
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script Filename
Dec 23, 2025
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Import
Dec 23, 2025
Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup
Dec 23, 2025
Coolify Stored Cross-Site Scripting (XSS) in Project Name Field
Aug 27, 2025
Coolify Docker Compose Directive Injection in Application Deployment Workflow
Aug 27, 2025
Coolify Git Repository Field Command Injection in Project Deployment Workflow
Aug 27, 2025
Coolify Vulnerable to Reflected XSS on Tag Search
Jan 24, 2025
Coolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)
Jan 24, 2025
Coolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE)
Jan 24, 2025
Coolify Vulnerable to OAuth Secrets Leak
Jan 24, 2025
Coolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE)
Jan 24, 2025
Coolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS)
Jan 24, 2025
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-64425 | Coolify has host header injection in forgot password | HIGH | 0.43% | Jan 5, 2026 |
| CVE-2025-64424 | Colify has command injection vulnerability in project git source | CRITICAL | 2.06% | Jan 5, 2026 |
| CVE-2025-64423 | Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links | HIGH | 0.35% | Jan 5, 2026 |
| CVE-2025-64422 | Rate-limit bypass on login via X-Forwarded-Host header | MEDIUM | 0.31% | Jan 5, 2026 |
| CVE-2025-64421 | Coolify has a privilege escalation - low privileged user can invite themselves as an admin user | HIGH | 0.30% | Jan 5, 2026 |
| CVE-2025-64420 | Coolify members can see private key of root user | CRITICAL | 0.53% | Jan 5, 2026 |
| CVE-2025-64419 | Coolify vulnerable to command injection via docker-compose.yaml parameters | CRITICAL | 0.66% | Jan 5, 2026 |
| CVE-2025-59955 | Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint | MEDIUM | 0.30% | Jan 5, 2026 |
| CVE-2025-59158 | Coolify has Stored XSS in Project Name | CRITICAL | 0.50% | Jan 5, 2026 |
| CVE-2025-59157 | Coolify has Git Repository RCE | CRITICAL | 1.82% | Jan 5, 2026 |
| CVE-2025-59156 | Coolify has Docker Compose Injection issue | CRITICAL | 1.00% | Jan 5, 2026 |
| CVE-2025-66213 | Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount Path | CRITICAL | 3.15% | Dec 23, 2025 |
| CVE-2025-66212 | Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration Filename | CRITICAL | 3.12% | Dec 23, 2025 |
| CVE-2025-66211 | Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script Filename | CRITICAL | 2.74% | Dec 23, 2025 |
| CVE-2025-66210 | Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Import | CRITICAL | 2.74% | Dec 23, 2025 |
| CVE-2025-66209 | Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup | CRITICAL | 3.88% | Dec 23, 2025 |
| CVE-2025-34157 | Coolify Stored Cross-Site Scripting (XSS) in Project Name Field | CRITICAL | 0.46% | Aug 27, 2025 |
| CVE-2025-34159 | Coolify Docker Compose Directive Injection in Application Deployment Workflow | CRITICAL | 0.96% | Aug 27, 2025 |
| CVE-2025-34161 | Coolify Git Repository Field Command Injection in Project Deployment Workflow | CRITICAL | 2.96% | Aug 27, 2025 |
| CVE-2025-24025 | Coolify Vulnerable to Reflected XSS on Tag Search | LOW | 0.23% | Jan 24, 2025 |
| CVE-2025-22612 | Coolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE) | CRITICAL | 0.62% | Jan 24, 2025 |
| CVE-2025-22611 | Coolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE) | CRITICAL | 0.49% | Jan 24, 2025 |
| CVE-2025-22610 | Coolify Vulnerable to OAuth Secrets Leak | MEDIUM | 0.39% | Jan 24, 2025 |
| CVE-2025-22609 | Coolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE) | CRITICAL | 0.75% | Jan 24, 2025 |
| CVE-2025-22608 | Coolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS) | MEDIUM | 0.36% | Jan 24, 2025 |
Showing 1 to 25 of 28 CVEs