PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64422 Coollabs CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T21:16:12.403Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Coolify versions starting from 4.0.0-beta.434, allowing unlimited credential stuffing and brute-force attempts due to bypassable rate limiting on the /login endpoint. Defenders managing servers, applications, and databases using Coolify should assess exposure and prioritize verifying the vulnerability and implementing compensating controls. The bypass is achieved by rotating the X-Forwarded-For header, which enables attackers to perform unlimited credential  

Vendor
Coollabs
Product
Coolify
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-05
Original CVE updated
2026-09-30
Advisory published
2026-01-05
Advisory updated
2026-09-30

Who should care

Defenders managing servers, applications, and databases using Coolify, particularly those using versions starting from 4.0.0-beta.434, should assess exposure and prioritize verifying the vulnerability and implementing compensating controls.

Why it matters

CVE-2025-64422 allows unlimited credential stuffing and brute-force attempts in Coolify versions starting from 4.0.0-beta.434 due to bypassable rate limiting on the /login endpoint.

  • Credential stuffing and brute-force attempts against user and admin accounts are possible due to bypassable rate limiting.
  • Defenders must verify exposure and assess the impact on their systems.
  • Implementing compensating controls, such as IP blocking or rate limiting, is necessary to mitigate the vulnerability.
  • Monitoring for suspicious activity and adjusting defensive measures as necessary is crucial.

Technical summary

The /login endpoint in Coolify versions starting from 4.0.0-beta.434 has a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header, enabling unlimited credential stuffing and brute-force attempts against user and admin accounts. This bypass allows attackers to perform credential stuffing and brute-force attacks without limitations, increasing the risk of successful attacks. Defenders should prioritize verifying exposure and assessing the impact of potential credential stuffing and brute-force attempts against user and admin accounts in Coolify versions starting from 4.0.0-beta.434. Implementing compensating controls, such as IP blocking or rate limiting, is necessary to  

Defensive priority

Defenders should prioritize verifying exposure and assessing the impact of potential credential stuffing and brute-force attempts against user and admin accounts in Coolify versions starting from 4.0.0-beta.434.

Recommended defensive actions

  • Verify exposure by checking Coolify versions starting from 4.0.0-beta.434 for bypassable rate limiting on the /login endpoint.
  • Assess the impact of potential credential stuffing and brute-force attempts against user and admin accounts.
  • Implement compensating controls, such as IP blocking or rate limiting, to mitigate the vulnerability.
  • Monitor for suspicious activity and adjust defensive measures as necessary.
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in Coolify versions starting from 4.0.0-beta.434, where the /login endpoint's rate limit can be bypassed by rotating the X-Forwarded-For header, enabling unlimited credential stuffing and brute-force attempts.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64422 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64422

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64422 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64422

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-688j-rm43-5r8x

    [email protected] - Exploit, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.