30 Total CVEs
30 AI Analyzed
0 CISA KEV
8 Critical

Profile

0% ended up actively exploited 0 of 30 added to CISA KEV
27% rated critical (CVSS 9.0+) 8 critical, 22 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

30 CVEs in the last 12 months

Products

  • Coolify25
  • coolify2

2 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-30 of 30 CVEs
CVE-2026-84694
Analyzed
8.8
coollabsio Coolify

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated at...

2026-09-02
CVE-2026-59734
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-10
CVE-2026-57498
Analyzed
9.6
coollabsio coolify

Coolify versions prior to 4.0.0-beta.474 contain an authorization flaw where Livewire web UI components fail to validate resource ownership, enabling...

2026-06-30
CVE-2026-42204
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-42200
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-42153
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-42143
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-41896
Analyzed
7.5
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-06-30
CVE-2026-34599
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34597
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-06-30
CVE-2026-34594
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-06-30
CVE-2026-34592
Analyzed
7.7
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-06-30
CVE-2026-34171
Analyzed
8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34168
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34158
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34153
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34152
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34058
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34057
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34048
Analyzed
9.9
coollabsio Coolify

Coolify terminal WebSocket routes fail to enforce team-based authorization, enabling low-privileged team members to execute commands on servers belong...

2026-07-07
CVE-2026-34047
Analyzed
9.9
coollabsio Coolify

Coolify terminal WebSocket routes fail to enforce authorization, allowing authenticated users to access and execute commands on unauthorized resources...

2026-07-07
CVE-2026-34044
Analyzed
7.7
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34038
Analyzed
9.9
coollabsio Coolify

Coolify contains an authenticated remote command injection vulnerability in application deployment handling, allowing remote code execution and sensit...

2026-07-07
CVE-2026-34037
Analyzed
9.9
coollabsio coolify

An authorization bypass vulnerability in Coolify allows authenticated users to access and manipulate resources belonging to other tenants.

2026-07-07
CVE-2026-34035
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-34034
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-07
CVE-2026-27957
Analyzed
8.8
coollabsio Coolify

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

2026-07-01
CVE-2025-64420
Analyzed
9.9
coollabsio Multiple Products

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-...

2026-01-06
CVE-2025-64419
Analyzed
9.6
coollabsio Multiple Products

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming...

2026-01-06
CVE-2025-59157
Analyzed
9.9
coollabsio Multiple Products

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Reposit...

2026-01-06