Technology · Coollabs
Coollabs Coolify vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 51 vulnerabilities in Coollabs Coolify: 0 in the last 7 days and 47 in the last 90 days, 6 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86117, was published on 5 September 2026.
- Last 7 days
- 0
- Last 90 days
- 47
- Critical, all time
- 6
- Exploited in the wild
- 0
About Coollabs Coolify
An open-source and self-hostable alternative to Heroku, Netlify, and Vercel.
Latest Coollabs Coolify vulnerabilities
- CVE-2026-86117: Coolify authentication bypass in OAuth callback handlerhighCVSS 8.1EPSS 0.7%
- CVE-2026-84694: Coolify command injection in Docker SSH environment variableshighCVSS 8.8EPSS 0.9%
- CVE-2026-15507: coollabsio Coolify missing authorization in Policy HandlermediumCVSS 6.3
- CVE-2026-59734: Coollabs Coolify OS command injection in health check configurationhighCVSS 8.8
- CVE-2026-42201: Coolify OS command injection in database credential fieldslowCVSS 3.3
- CVE-2026-34158: Coolabsio Coolify OS command injection in Docker Compose commandshighCVSS 8.8
- CVE-2026-42200: Coollabsio Coolify path traversal in PostgreSQL init scriptshighCVSS 8.8
- CVE-2026-42172: Coollabs Coolify insufficient session expiration for API tokenslowCVSS 3.1
- CVE-2026-42147: Coollabsio Coolify SSRF in S3 storage endpoint validationmediumCVSS 4.9
- CVE-2026-42145: Coollabsio Coolify unrestricted file upload in database backup restorelowCVSS 3.1
- CVE-2026-42143: Coollabsio Coolify OS command injection in persistent volume nameshighCVSS 8.8
- CVE-2026-34198: Coolify account takeover via host header injection in password resetmediumCVSS 5.3
- CVE-2026-34171: Coolify account takeover via CSRF in invitation endpointhighCVSS 8
- CVE-2026-34170: coollabsio Coolify SSRF in GitHub App configurationmediumCVSS 4.3
- CVE-2026-34168: Coollabs Coolify OS command injection in LocalPersistentVolume namehighCVSS 8.8
- CVE-2026-34152: Coolabsio Coolify OS command injection in deployment commandshighCVSS 8.8
- CVE-2026-34149: Coolify OS command injection in DatabaseBackupJoblowCVSS 3.3
- CVE-2026-34058: Coollabsio Coolify OS command injection in Server ResourceshighCVSS 8.8
- CVE-2026-34057: Coolify command injection in database import componenthighCVSS 8.8
- CVE-2026-34048: Coolify improper authorization in terminal websocket routescriticalCVSS 9.9
- CVE-2026-34047: Coolify incorrect authorization in terminal WebSocket routescriticalCVSS 9.9
- CVE-2026-34044: Coolify IDOR in Logs component allows cross-team log accesshighCVSS 7.7
- CVE-2026-34037: Coolify cross-tenant resource cloning in ResourceOperations.phpcriticalCVSS 9.9
- CVE-2026-34035: coollabsio Coolify command injection in Log Drain configurationhighCVSS 8.8
- CVE-2026-34034: Coolify OS command injection in Sentinel token settingshighCVSS 8.8
Most severe Coollabs Coolify vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34048: Coolify improper authorization in terminal websocket routescriticalCVSS 9.9
- CVE-2026-34047: Coolify incorrect authorization in terminal WebSocket routescriticalCVSS 9.9
- CVE-2026-34037: Coolify cross-tenant resource cloning in ResourceOperations.phpcriticalCVSS 9.9
- CVE-2026-34038: Coollabsio Coolify command injection in application deployment handlingcriticalCVSS 9.9
- CVE-2026-57498: Coolify authorization bypass in Livewire UI componentscriticalCVSS 9.6
- CVE-2025-34157: Coollabs Coolify stored XSS in project creation workflowcriticalCVSS 9EPSS 0.4%
- CVE-2025-34161: coollabsio Coolify remote code execution in Git Repository fieldhighCVSS 8.8EPSS 3.7%
- CVE-2025-34159: Coolabs Coolify remote code execution via Docker Compose injectionhighCVSS 8.8EPSS 0.9%
- CVE-2026-84694: Coolify command injection in Docker SSH environment variableshighCVSS 8.8EPSS 0.9%
- CVE-2026-59734: Coollabs Coolify OS command injection in health check configurationhighCVSS 8.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 11 | 1 | |
| 6 Jul 2026 | 34 | 4 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 2 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/coolify.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Coollabs Coolify vulnerabilities", https://junglewise.ai/threats/technologies/coolify, 26 September 2026.