Executive brief
Coolify, an open-source tool for managing servers and applications, contains a security flaw in how it verifies GitLab webhooks. An attacker could use a specialized timing attack to guess the secret security token used to authenticate these webhooks. If successful, an attacker could trigger unauthorized software deployments or disrupt the automated build process.
Technical details
The GitLab webhook endpoint in Coolify (specifically in `app/Http/Controllers/Webhook/Gitlab.php`) used the non-constant-time `!==` operator to validate the `X-Gitlab-Token` against the stored secret. Because PHP's standard comparison returns as soon as a mismatch is found, an attacker can measure response time differences to perform a side-channel timing attack. By iteratively testing characters and measuring the slight delays caused by matching prefixes, an attacker can reconstruct the valid webhook secret. This vulnerability is fixed in version 4.0.0-beta.461 by implementing the `hash_equals()` function for constant-time comparison.
Affected products
- coollabsio Coolify < 4.0.0-beta.461
Timeline
- 2026-06-25: advisory: GitHub Security Advisory published by vendor
- 2026-06-30: disclosed: CVE published to NVD
- 2026-06-30: patched: Vulnerability fixed in version 4.0.0-beta.461