Coolify · Coolify · CVE-2026-41899
**Name of the Vulnerable Software and Affected Versions**
Coolify versions prior to 4.0.0-beta.474
**Description**
The application lacks authentication, rate limiting, and input validation at the 'POST /api/feedback' endpoint. This allows arbitrary content to be forwarded directly to a Discord webhook, which can lead to spam, content injection, and webhook abuse.
**Recommendations**
Update to version 4.0.0-beta.474.