PatchSiren cyber security CVE debrief
CVE-2025-64425 Coollabs CVE debrief
A vulnerability in Coolify versions up to and including v4.0.0-beta.434 allows an attacker to initiate a password reset for a victim and modify the host header of the request to a malicious value. This can lead to the victim receiving a password reset email with a link to the malicious host, potentially allowing the attacker to capture the reset token and take over the victim's account.
- Vendor
- Coollabs
- Product
- Coolify
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-05
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-05
- Advisory updated
- 2026-09-30
Who should care
Defenders responsible for Coolify deployments, especially those using versions up to and including v4.0.0-beta.434, should assess exposure and prioritize verification and mitigation efforts.
Why it matters
Defenders should care about CVE-2025-64425 because it allows attackers to potentially take over accounts through manipulated password reset links in Coolify deployments. Roles responsible for Coolify deployments, especially those using vulnerable versions, should assess exposure and prioritize verification and mitigation efforts.
- Potential account takeover through password reset manipulation
- Exposure of sensitive authentication information
- Need for verification of affected versions and deployments
- Priority for patching or applying compensating controls
Technical summary
The vulnerability allows an attacker to initiate a password reset for a victim and modify the host header of the request to a malicious value, potentially leading to account takeover. This issue affects Coolify versions up to and including v4.0.0-beta.434. An attacker can exploit this by sending a password reset request with a modified host header, causing the victim to receive a password reset email with a link to the malicious host. If the victim clicks this link, their reset token is sent to the attacker's server, allowing the attacker to use it to change the victim's password and take over their account.
Defensive priority
Defenders should prioritize verifying exposure in their Coolify deployments, especially those using versions up to and including v4.0.0-beta.434, and assess the feasibility of compensating controls until an official patch is available.
Recommended defensive actions
- Verify exposure in Coolify deployments, especially those using versions up to and including v4.0.0-beta.434
- Assess the feasibility of compensating controls until an official patch is available
- Monitor for suspicious password reset activity
- Consider implementing additional security measures for authentication and account management
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
Evidence notes
The vulnerability is described in the CVE Program record and the NVD vulnerability detail page. The source reference provides additional information from the vendor's advisory. However, details about the exploit and affected scope are limited. Defenders should verify exposure in their Coolify deployments, especially those using versions up to and including v4.0.0-beta.434, and assess the feasibility of compensating controls until an official patch is available. The vendor's advisory and CVE record provide the most authoritative and up
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64425 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64425
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64425 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64425
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-f737-2p93-g2cw
[email protected] - Exploit, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.