Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimited credential stuffing and brute-force attempts against user and admin accounts. As of time of publication, it is unclear if a patch is available.
Conclusion & alert: CVE-2025-64422 is rated Exploit Available (50/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.05%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-03 | 0.05% | 0.05% | -0.01% |
| 2 | 2026-02-16 | 0.04% | 0.05% | +0.02% |
| 3 | 2026-01-13 | — | 0.04% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| coollabs | coolify | < 4.0.0 | cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta100:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta101:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta102:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta103:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta104:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta105:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta106:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta107:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta108:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta109:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta110:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta111:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta112:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta113:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta114:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta115:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta116:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta117:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta118:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta119:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta120:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta121:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta122:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta123:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta124:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta125:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta126:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta127:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta128:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta129:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta130:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta131:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta132:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta133:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta134:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta135:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta136:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta137:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta138:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta139:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta140:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta141:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta142:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta143:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta144:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta145:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta146:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta147:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta148:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta149:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta150:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta151:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta152:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta153:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta154:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta155:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta156:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta157:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta158:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta159:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta160:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta161:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta162:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta163:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta164:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta165:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta166:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta167:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta168:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta169:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta170:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta171:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta172:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta173:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta174:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta175:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta176:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta177:*:*:*:*:*:* |
| coollabs | coolify | 4.0.0 | cpe:2.3:a:coollabs:coolify:4.0.0:beta178:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/coollabsio/coolify/security/advisories/GHSA-688j-rm43-5r8x | Exploit Vendor Advisory |