Coolify

Coollabs · 28 CVEs

CVE-2025-64425
HIGH

Coolify has host header injection in forgot password

Jan 5, 2026

CVE-2025-64424
CRITICAL

Colify has command injection vulnerability in project git source

Jan 5, 2026

CVE-2025-64423
HIGH

Coolify has a Privilege Escalation - low privileged users can see and use admin invitation links

Jan 5, 2026

CVE-2025-64422
MEDIUM

Rate-limit bypass on login via X-Forwarded-Host header

Jan 5, 2026

CVE-2025-64421
HIGH

Coolify has a privilege escalation - low privileged user can invite themselves as an admin user

Jan 5, 2026

CVE-2025-64420
CRITICAL

Coolify members can see private key of root user

Jan 5, 2026

CVE-2025-64419
CRITICAL

Coolify vulnerable to command injection via docker-compose.yaml parameters

Jan 5, 2026

CVE-2025-59955
MEDIUM

Coolify leaksensitive information `email_change_code` in `/api/v1/teams/{team_id | current}/members` API endpoint

Jan 5, 2026

CVE-2025-59158
CRITICAL

Coolify has Stored XSS in Project Name

Jan 5, 2026

CVE-2025-59157
CRITICAL

Coolify has Git Repository RCE

Jan 5, 2026

CVE-2025-59156
CRITICAL

Coolify has Docker Compose Injection issue

Jan 5, 2026

CVE-2025-66213
CRITICAL

Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in File Storage Directory Mount Path

Dec 23, 2025

CVE-2025-66212
CRITICAL

Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Dynamic Proxy Configuration Filename

Dec 23, 2025

CVE-2025-66211
CRITICAL

Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in PostgreSQL Init Script Filename

Dec 23, 2025

CVE-2025-66210
CRITICAL

Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Import

Dec 23, 2025

CVE-2025-66209
CRITICAL

Coolify Vulnerable to Authenticated Remote Code Execution via Command Injection in Database Backup

Dec 23, 2025

CVE-2025-34157
CRITICAL

Coolify Stored Cross-Site Scripting (XSS) in Project Name Field

Aug 27, 2025

CVE-2025-34159
CRITICAL

Coolify Docker Compose Directive Injection in Application Deployment Workflow

Aug 27, 2025

CVE-2025-34161
CRITICAL

Coolify Git Repository Field Command Injection in Project Deployment Workflow

Aug 27, 2025

CVE-2025-24025
LOW

Coolify Vulnerable to Reflected XSS on Tag Search

Jan 24, 2025

CVE-2025-22612
CRITICAL

Coolify Vulnerable to Private Key Enumeration on Onboarding resulting in Remote Command Execution (RCE)

Jan 24, 2025

CVE-2025-22611
CRITICAL

Coolify vulnerable to Privilege Escalation resulting in Remote Command Execution (RCE)

Jan 24, 2025

CVE-2025-22610
MEDIUM

Coolify Vulnerable to OAuth Secrets Leak

Jan 24, 2025

CVE-2025-22609
CRITICAL

Coolify Vulnerable to Private Key Hijacking / Remote Command Execution (RCE)

Jan 24, 2025

CVE-2025-22608
MEDIUM

Coolify Vulnerable to Revocation of Arbitrary Team Invitations (DOS)

Jan 24, 2025

Showing 1 to 25 of 28 CVEs