<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>coollabsio CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/coollabsio/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/coollabsio.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical coollabsio vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Sun, 06 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-86117 · CVSS 8.1 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-86117/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-86117</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Sun, 06 Sep 2026 12:00:00 GMT</pubDate>
      <description>Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address without verifying provider assertions or binding OAuth identities. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-84694 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-84694/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-84694</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Wed, 02 Sep 2026 12:00:00 GMT</pubDate>
      <description>Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Fix documented: 4.2.0 (CVE record). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-59734 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-59734/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-59734</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Fri, 10 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34034 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34034/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34034</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34035 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34035/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34035</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34037 · CVSS 9.9 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34037/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34037</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>An authorization bypass vulnerability in Coolify allows authenticated users to access and manipulate resources belonging to other tenants. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34038 · CVSS 9.9 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34038/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34038</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify contains an authenticated remote command injection vulnerability in application deployment handling, allowing remote code execution and sensitive data exfiltration. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34044 · CVSS 7.7 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34044/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34044</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34047 · CVSS 9.9 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34047/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34047</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify terminal WebSocket routes fail to enforce authorization, allowing authenticated users to access and execute commands on unauthorized resources. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34048 · CVSS 9.9 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34048/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34048</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify terminal WebSocket routes fail to enforce team-based authorization, enabling low-privileged team members to execute commands on servers belonging to other teams. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34057 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34057/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34057</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34058 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34058/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34058</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34152 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34152/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34152</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34153 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34153/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34153</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34158 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34158/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34158</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34168 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34168/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34168</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34171 · CVSS 8.0 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34171/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34171</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34599 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34599/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34599</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-42143 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-42143/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-42143</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-42153 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-42153/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-42153</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-42200 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-42200/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-42200</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-42204 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-42204/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-42204</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-27957 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-27957/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-27957</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34592 · CVSS 7.7 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34592/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34592</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34594 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34594/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34594</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-34597 · CVSS 8.8 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-34597/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-34597</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-41896 · CVSS 7.5 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-41896/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-41896</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-57498 · CVSS 9.6 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2026-57498/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2026-57498</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 30 Jun 2026 12:00:00 GMT</pubDate>
      <description>Coolify versions prior to 4.0.0-beta.474 contain an authorization flaw where Livewire web UI components fail to validate resource ownership, enabling cross-team resource manipulation. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-59157 · CVSS 9.9 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2025-59157/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2025-59157</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 06 Jan 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-64419 · CVSS 9.6 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2025-64419/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2025-64419</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 06 Jan 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2025-64420 · CVSS 9.9 · coolify</title>
      <link>https://cvebrief.com/cve/cve-2025-64420/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-coollabsio-CVE-2025-64420</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/coollabsio.png" medium="image" type="image/png"/>
      <pubDate>Tue, 06 Jan 2026 12:00:00 GMT</pubDate>
      <description>Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Fix documented (OSV.dev). Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
