CVE-2026-42145
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload
CVSS
3.1
Bajo
EPSS
0.3%
p16
KEV
—
Exploit Today
5
0-100
Publicado: 7 jul 2026 · Última mod.: 9 jul 2026 · CWE-434 · CWE-770
0.3%EPSS · 30 días0.3%
2026-07-072026-07-20
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. This issue is fixed in version 4.0.0-beta.474.
- github.comhttps://github.com/coollabsio/coolify/commit/e6a6446daeace2999fb77888a611a3271812911f
- github.comhttps://github.com/coollabsio/coolify/pull/9667
- github.comhttps://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474
- github.comhttps://github.com/coollabsio/coolify/security/advisories/GHSA-66gv-g2w9-6wxp
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-562919.8 CRÍ94.5%
KEV—78Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability10dCVE-2026-562909.8 CRÍ85.5%
KEV—76Joomlack Page Builder Improper Access Control Vulnerability13dCVE-2026-489089.8 CRÍ72.6%
KEV—72JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability13dCVE-2026-489399.8 CRÍ71.5%
KEV—71iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability10dCVE-2023-388368.8 ALT99.3%
——30File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks.12dCVE-2026-217107.5 ALT97.8%
——29A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`.
When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`.
* This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**6d