Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

00Gxd14G

#28131of 56,330
9.6Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2026-56138
3.1
2026-07-07
Coolify · Coolify · CVE-2026-42145
**Name of the Vulnerable Software and Affected Versions** Coolify versions prior to 4.0.0-beta.474 **Description** An issue exists in the file upload endpoint `app/Http/Controllers/UploadController.php` used for database backup restore uploads. The system fails to enforce file type or size validation, which allows an authenticated user to upload oversized or unexpected files, potentially impacting service availability. **Recommendations** Update to version 4.0.0-beta.474.
PT-2026-56024
6.5
2026-07-06
Coolify · Coolify · CVE-2026-41899
**Name of the Vulnerable Software and Affected Versions** Coolify versions prior to 4.0.0-beta.474 **Description** The application lacks authentication, rate limiting, and input validation at the 'POST /api/feedback' endpoint. This allows arbitrary content to be forwarded directly to a Discord webhook, which can lead to spam, content injection, and webhook abuse. **Recommendations** Update to version 4.0.0-beta.474.