Coolify Vulnerabilities Allow Full Server Compromise
These articles are AI-generated summaries. Please check the original sources for full details.
Coolify Discloses 11 Critical Flaws
Coolify, a self-hosting platform, has revealed 11 critical vulnerabilities, ranging in CVSS score up to 10.0, that could allow attackers to gain full control of compromised servers. These flaws, discovered by security researchers, include command injection and information disclosure vulnerabilities.
Why This Matters
Self-hosted platforms often present a larger attack surface due to reliance on individual administrators for patching and configuration. Ideal security models assume timely updates, but real-world deployment lags are common. The presence of 52,890 exposed Coolify hosts as of January 8, 2026, highlights the potential scale of impact if these vulnerabilities are exploited, potentially resulting in widespread infrastructure compromise and data breaches.
Key Insights
- 52,890: Number of exposed Coolify hosts as of January 8, 2026, according to Censys.
- Command Injection: Multiple vulnerabilities (CVE-2025-66209, CVE-2025-66210, etc.) allow attackers to execute arbitrary commands on the server, bypassing security controls.
- Root Key Disclosure: CVE-2025-64420 enables low-privileged users to view the root user’s private key, granting unauthorized SSH access.
Practical Applications
- Use Case: Organizations using Coolify for self-hosting applications must immediately update to the patched versions to prevent exploitation.
- Pitfall: Ignoring vulnerability disclosures in self-hosted software can lead to complete system takeover and data loss.
References:
Continue reading
Next article
CrowdStrike to Acquire SGNL for $740M to Bolster Identity Security
Related Content
Chainlit AI Framework Vulnerabilities Enable Data Theft and SSRF Attacks
High-severity flaws in the Chainlit AI framework (CVE-2026-22218 & CVE-2026-22219) could allow attackers to steal files, leak API keys, and perform SSRF attacks.
cPanel and WHM Patch Critical Vulnerabilities to Prevent RCE and Privilege Escalation
cPanel and WHM released patches for three vulnerabilities, including two CVSS 8.8 flaws, to prevent arbitrary code execution and privilege escalation.
React2Shell Exploitation Delivers Crypto Miners and New Malware Across Multiple Sectors
Critical React Server Components flaw (CVE-2025-55182) fuels automated attacks dropping miners and multiple new Linux malware families.