Executive brief
Coolify is an open-source platform used to manage servers, applications, and databases. A security issue was identified where API access tokens did not have an expiration date, meaning that if a token was ever leaked or stolen, it would remain valid forever. This could allow unauthorized individuals to maintain long-term access to a company's infrastructure management tools unless the token was manually revoked.
Technical details
Coolify suffered from insufficient session expiration (CWE-613) in its API authentication layer. Prior to version 4.0.0-beta.474, personal API tokens generated via Laravel Sanctum did not have an 'expires_at' value enforced, resulting in infinite TTL. An attacker who obtains a leaked token can maintain persistent access to the Coolify API. The fix introduces optional expiration durations (1, 7, 30, 60, or 90 days), implements an hourly pruning job for expired tokens, and adds proactive expiration notifications.
Affected products
- coollabsio Coolify < 4.0.0-beta.474
Timeline
- 2026-04-20: patched: Fix merged into the repository.
- 2026-04-21: advisory: Release v4.0.0-beta.474 published.
- 2026-07-07: disclosed: CVE-2026-42172 published.