Junglewise Threat Intelligence

CVE-2026-27882: Coolify timing attack in GitLab webhook validation

CVE-2026-27882 · Severity: medium · CVSS 4.8 · Published 2026-06-30

Executive brief

Coolify, an open-source tool for managing servers and applications, contains a security flaw in how it verifies GitLab webhooks. An attacker could use a specialized timing attack to guess the secret security token used to authenticate these webhooks. If successful, an attacker could trigger unauthorized software deployments or disrupt the automated build process.

Technical details

The GitLab webhook endpoint in Coolify (specifically in `app/Http/Controllers/Webhook/Gitlab.php`) used the non-constant-time `!==` operator to validate the `X-Gitlab-Token` against the stored secret. Because PHP's standard comparison returns as soon as a mismatch is found, an attacker can measure response time differences to perform a side-channel timing attack. By iteratively testing characters and measuring the slight delays caused by matching prefixes, an attacker can reconstruct the valid webhook secret. This vulnerability is fixed in version 4.0.0-beta.461 by implementing the `hash_equals()` function for constant-time comparison.

Affected products

  • coollabsio Coolify < 4.0.0-beta.461

Timeline

  • 2026-06-25: advisory: GitHub Security Advisory published by vendor
  • 2026-06-30: disclosed: CVE published to NVD
  • 2026-06-30: patched: Vulnerability fixed in version 4.0.0-beta.461

References