Junglewise Threat Intelligence

CVE-2026-42145: Coollabsio Coolify unrestricted file upload in database backup restore

CVE-2026-42145 · Severity: low · CVSS 3.1 · Published 2026-07-07

Executive brief

Coolify, an open-source tool for managing servers and databases, contained a vulnerability in its database backup restoration feature. An authorized user could upload files of any type or size, potentially leading to server crashes or service outages by filling up the system's storage. This issue could disrupt business operations and prevent new application deployments until the storage is cleared.

Technical details

The database backup restore endpoint (app/Http/Controllers/UploadController.php) in Coolify prior to version 4.0.0-beta.474 failed to implement file type or size validation. An authenticated attacker with database management permissions could upload arbitrary files (e.g., PHP scripts or large binaries) via the POST /upload/backup/{databaseUuid} endpoint. Additionally, the application used a predictable filename generation scheme based on md5(time()), which could assist in locating uploaded files. While the primary impact is service availability via disk exhaustion (CWE-770), the lack of MIME type validation (CWE-434) poses a potential risk of remote code execution if the files are later executed or processed. The vulnerability is resolved in version 4.0.0-beta.474 by implementing a 10 GiB size limit and an extension allowlist.

Affected products

  • coollabsio Coolify < 4.0.0-beta.474

Timeline

  • 2026-04-20: patched: Fix merged into the development branch.
  • 2026-04-21: advisory: Release v4.0.0-beta.474 published.
  • 2026-07-02: disclosed: Security advisory GHSA-66gv-g2w9-6wxp published.
  • 2026-07-07: other: CVE-2026-42145 published to NVD.

References