Executive brief
Coolify, an open-source tool for managing servers and databases, contained a vulnerability in its database backup restoration feature. An authorized user could upload files of any type or size, potentially leading to server crashes or service outages by filling up the system's storage. This issue could disrupt business operations and prevent new application deployments until the storage is cleared.
Technical details
The database backup restore endpoint (app/Http/Controllers/UploadController.php) in Coolify prior to version 4.0.0-beta.474 failed to implement file type or size validation. An authenticated attacker with database management permissions could upload arbitrary files (e.g., PHP scripts or large binaries) via the POST /upload/backup/{databaseUuid} endpoint. Additionally, the application used a predictable filename generation scheme based on md5(time()), which could assist in locating uploaded files. While the primary impact is service availability via disk exhaustion (CWE-770), the lack of MIME type validation (CWE-434) poses a potential risk of remote code execution if the files are later executed or processed. The vulnerability is resolved in version 4.0.0-beta.474 by implementing a 10 GiB size limit and an extension allowlist.
Affected products
- coollabsio Coolify < 4.0.0-beta.474
Timeline
- 2026-04-20: patched: Fix merged into the development branch.
- 2026-04-21: advisory: Release v4.0.0-beta.474 published.
- 2026-07-02: disclosed: Security advisory GHSA-66gv-g2w9-6wxp published.
- 2026-07-07: other: CVE-2026-42145 published to NVD.