Executive brief
Coolify, an open-source tool for managing servers and databases, is vulnerable to a security flaw where authenticated users can force the server to make unauthorized requests to internal network addresses. By providing a specially crafted S3 storage endpoint, an attacker could potentially access sensitive cloud metadata, scan internal network ports, or interact with private services like databases that are not intended to be exposed. This could lead to the theft of cloud credentials or unauthorized access to internal infrastructure.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Coolify's S3 storage management component. The 'testConnection()' method in 'app/Models/S3Storage.php' fails to validate user-supplied endpoint URLs against private or internal IP ranges, relying only on a basic URL format check. An authenticated attacker with storage management permissions can configure a malicious S3 endpoint (e.g., pointing to 169.254.169.254 or localhost) and trigger a connection test. This causes the server to send an S3 ListObjectsV2 request to the target, potentially leaking cloud IAM credentials via metadata services or allowing internal port scanning. The issue was addressed in version 4.0.0-beta.474 by implementing the 'SafeWebhookUrl' validation rule on S3 endpoints.
Affected products
- coollabsio Coolify < 4.0.0-beta.474
Timeline
- 2026-04-20: patched: Fix committed to repository
- 2026-04-21: advisory: Release v4.0.0-beta.474 published
- 2026-07-02: disclosed: Security advisory GHSA-pwm4-w33c-wjf3 published
- 2026-07-07: advisory: CVE-2026-42147 published to NVD