CVE 5.5 MEDIUM

Rate-limit bypass on login via X-Forwarded-Host header_CVE-2025-64422

5.5 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimited credential stuffing and brute-force attempts against user and admin accounts. As of time of publication, it is unclear if a patch is available.

Basic Information

ID CVE-2025-64422
Source GitHub_M
Published Jan 5, 2026 at 20:29
Modified Jan 5, 2026 at 20:38

Affected Product

Vendor coollabsio
Product coolify
Version >= 4.0.0-beta.434
Affected Versions coollabsio coolify >= 4.0.0-beta.434

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.