VulnSea

coolify vulnerabilities

CVEs whose affected-version data names the coolify package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-86117High· 8.1
2w ago

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities.…

Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities.…

Twilightcoollabsio · coolifyEPSS 0.42%via NVD
CVE-2025-34161High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell …

Midnightcoollabs · coolifyEPSS 3.0%via NVD
CVE-2025-34159High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Do…

Midnightcoollabs · coolifyEPSS 0.96%via NVD
CVE-2025-34157Critical· 9.0PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name con…

Abyssalcoollabs · coolifyEPSS 0.46%via NVD
coolify vulnerabilities (CVEs) · VulnSea