CVE Database
/

CVE-2025-64422

Back to search

CVE-2025-64422

Published: Jan 5, 2026

Modified: Jan 5, 2026

PUBLISHED

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimited credential stuffing and brute-force attempts against user and admin accounts. As of time of publication, it is unclear if a patch is available.

VendorProductVersions

coollabsio

coolify

affected
>= 4.0.0-beta.434

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now