Executive brief
Coolify, an open-source tool for managing servers and databases, contained a vulnerability in its feedback submission system. Because this system lacked authentication and rate limits, unauthorized users could flood the platform with spam or inject malicious content into the administrator's Discord notifications. This could lead to service disruptions in communication channels or be used to spread phishing links to staff and community members.
Technical details
The 'POST /api/feedback' endpoint in Coolify was implemented without authentication middleware, rate limiting, or input validation. The 'content' parameter from the request was passed directly to a configured Discord webhook. An unauthenticated remote attacker could exploit this to perform a Denial of Service (DoS) against the Discord channel by exhausting webhook rate limits, or perform content injection (such as phishing or @everyone mentions) by sending crafted JSON payloads. The fix, introduced in version 4.0.0-beta.474, implements a 'throttle:feedback' middleware (3 requests per minute), input validation (10-2000 characters), and disables mention parsing in the Discord webhook configuration.
Affected products
- coollabsio Coolify < 4.0.0-beta.474
Timeline
- 2026-04-19: patched: Fix merged via pull request 9653
- 2026-07-02: advisory: GitHub Security Advisory published
- 2026-07-06: disclosed: CVE published to NVD