CVE-2026-41899: Coollabsio Coolify
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forwarded directly to a Discord webhook and enabling spam, content injection, and webhook abuse. This issue is fixed in version 4.0.0-beta.474.
Affected products
- Coollabsio Coolify: before 4.0.0-beta.474 (fixed in 4.0.0-beta.474)
Published 2026-07-06. Last modified 2026-07-07.