PatchSiren cyber security CVE debrief
CVE-2025-64422 Coollabs CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-01-05T21:16:12.403Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Coolify versions starting from 4.0.0-beta.434, allowing unlimited credential stuffing and brute-force attempts due to bypassable rate limiting on the /login endpoint. Defenders managing servers, applications, and databases using Coolify should assess exposure and prioritize verifying the vulnerability and implementing compensating controls. The bypass is achieved by rotating the X-Forwarded-For header, which enables attackers to perform unlimited credential
- Vendor
- Coollabs
- Product
- Coolify
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-05
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-05
- Advisory updated
- 2026-09-30
Who should care
Defenders managing servers, applications, and databases using Coolify, particularly those using versions starting from 4.0.0-beta.434, should assess exposure and prioritize verifying the vulnerability and implementing compensating controls.
Why it matters
CVE-2025-64422 allows unlimited credential stuffing and brute-force attempts in Coolify versions starting from 4.0.0-beta.434 due to bypassable rate limiting on the /login endpoint.
- Credential stuffing and brute-force attempts against user and admin accounts are possible due to bypassable rate limiting.
- Defenders must verify exposure and assess the impact on their systems.
- Implementing compensating controls, such as IP blocking or rate limiting, is necessary to mitigate the vulnerability.
- Monitoring for suspicious activity and adjusting defensive measures as necessary is crucial.
Technical summary
The /login endpoint in Coolify versions starting from 4.0.0-beta.434 has a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header, enabling unlimited credential stuffing and brute-force attempts against user and admin accounts. This bypass allows attackers to perform credential stuffing and brute-force attacks without limitations, increasing the risk of successful attacks. Defenders should prioritize verifying exposure and assessing the impact of potential credential stuffing and brute-force attempts against user and admin accounts in Coolify versions starting from 4.0.0-beta.434. Implementing compensating controls, such as IP blocking or rate limiting, is necessary to
Defensive priority
Defenders should prioritize verifying exposure and assessing the impact of potential credential stuffing and brute-force attempts against user and admin accounts in Coolify versions starting from 4.0.0-beta.434.
Recommended defensive actions
- Verify exposure by checking Coolify versions starting from 4.0.0-beta.434 for bypassable rate limiting on the /login endpoint.
- Assess the impact of potential credential stuffing and brute-force attempts against user and admin accounts.
- Implement compensating controls, such as IP blocking or rate limiting, to mitigate the vulnerability.
- Monitor for suspicious activity and adjust defensive measures as necessary.
- Review relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in Coolify versions starting from 4.0.0-beta.434, where the /login endpoint's rate limit can be bypassed by rotating the X-Forwarded-For header, enabling unlimited credential stuffing and brute-force attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64422 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64422
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64422 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64422
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-688j-rm43-5r8x
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.