PT-2026-53890 · Coolify · Coolify

·

CVE-2026-27882

·

Published

2026-06-30

·

Updated

2026-06-30

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Coolify versions prior to 4.0.0-beta.461
Description The GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation allows for timing attacks, where an attacker can gradually discover the secret token by measuring differences in response times. A timing attack is a side-channel attack where the attacker attempts to compromise a system by analyzing the time it takes to execute specific algorithms.
Recommendations Update to version 4.0.0-beta.461.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27882
GHSA-X525-46RQ-MR8C

Affected Products

Coolify