CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical Coolify Flaws Enable Full Server Compromise on Self-Hosted Instances

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Eleven critical vulnerabilities in Coolify, an open-source self-hosting platform, have been disclosed, enabling authentication bypass and remote code execution on self-hosted instances. These flaws could lead to full server compromise if exploited. The vulnerabilities affect various functionalities, including database management, proxy configuration, and file storage. The affected versions and fixes are specified, with some versions having unclear fix statuses. As of January 8, 2026, there are approximately 52,890 exposed Coolify hosts worldwide, primarily in Germany, the U.S., France, Brazil, and Finland. While no exploitation in the wild has been reported, users are urged to apply patches promptly due to the severity of the flaws.

Timeline

  1. 08.01.2026 11:53 1 articles · 23h ago

    Eleven Critical Coolify Flaws Disclosed

    On January 8, 2026, cybersecurity researchers disclosed eleven critical vulnerabilities in Coolify, an open-source self-hosting platform. These flaws enable authentication bypass and remote code execution on self-hosted instances, potentially leading to full server compromise. The vulnerabilities affect various functionalities, including database management, proxy configuration, and file storage. The affected versions and fixes are specified, with some versions having unclear fix statuses. As of the disclosure date, there are approximately 52,890 exposed Coolify hosts worldwide, primarily in Germany, the U.S., France, Brazil, and Finland. While no exploitation in the wild has been reported, users are urged to apply patches promptly due to the severity of the flaws.

    Show sources

Information Snippets