PT-2026-53890 · Coolify · Coolify
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Coolify versions prior to 4.0.0-beta.461
Description
The GitLab webhook endpoint uses a non-constant-time string comparison operator (!==) to validate the webhook secret token. This implementation allows for timing attacks, where an attacker can gradually discover the secret token by measuring differences in response times. A timing attack is a side-channel attack where the attacker attempts to compromise a system by analyzing the time it takes to execute specific algorithms.
Recommendations
Update to version 4.0.0-beta.461.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coolify