PT-2026-1331 · Coolify · Coolify

Published

2026-01-05

·

Updated

2026-01-12

·

CVE-2025-64422

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Coolify versions 4.0.0-beta.434 and later
Description Coolify is a self-hostable tool for managing servers, applications, and databases. A rate limit on the /login endpoint can be bypassed by rotating the X-Forwarded-For header. This allows unlimited credential stuffing and brute-force attempts against user and admin accounts. The vulnerable API endpoint is /login and the vulnerable parameter is X-Forwarded-For.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-64422
GHSA-688J-RM43-5R8X

Affected Products

Coolify