coolLabs Coolify是coolLabs团队开源的一个开源和自托管的 Heroku/Netlify/Vercel 替代品。 CoolLabs Coolify 4.0.0-beta.461之前版本存在侧信道信息泄露漏洞,该漏洞源于使用非常量时间字符串比较运算符(!==)验证webhook秘密令牌,容易受到计时攻击,可能导致攻击者通过测量响应时间差异逐步发现秘密令牌。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.461 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.461 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27957 | 8.8 HIGH | Coolify: Authenticated RCE via command injection in CA certificate management feature |
| CVE-2026-27955 | 6.6 MEDIUM | Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()` |
| CVE-2026-27883 | 5.0 MEDIUM | Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure |
| CVE-2026-27881 | 5.0 MEDIUM | Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} ( |
| CVE-2026-27956 | 4.3 MEDIUM | Coolify: Cross-team application domain enumeration via domains_by_server endpoint |
No comments yet