Junglewise Threat Intelligence

CVE-2026-42172: Coollabs Coolify insufficient session expiration for API tokens

CVE-2026-42172 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: Coollabs Coolify. Vendors: Coollabs.

Executive brief

Coolify is an open-source platform used to manage servers, applications, and databases. A security issue was identified where API access tokens did not have an expiration date, meaning that if a token was ever leaked or stolen, it would remain valid forever. This could allow unauthorized individuals to maintain long-term access to a company's infrastructure management tools unless the token was manually revoked.

Technical details

Coolify suffered from insufficient session expiration (CWE-613) in its API authentication layer. Prior to version 4.0.0-beta.474, personal API tokens generated via Laravel Sanctum did not have an 'expires_at' value enforced, resulting in infinite TTL. An attacker who obtains a leaked token can maintain persistent access to the Coolify API. The fix introduces optional expiration durations (1, 7, 30, 60, or 90 days), implements an hourly pruning job for expired tokens, and adds proactive expiration notifications.

Affected products

  • coollabsio Coolify < 4.0.0-beta.474

Timeline

  • 2026-04-20: patched: Fix merged into the repository.
  • 2026-04-21: advisory: Release v4.0.0-beta.474 published.
  • 2026-07-07: disclosed: CVE-2026-42172 published.

References

Related threats