PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-64425 Coollabs CVE debrief

A vulnerability in Coolify versions up to and including v4.0.0-beta.434 allows an attacker to initiate a password reset for a victim and modify the host header of the request to a malicious value. This can lead to the victim receiving a password reset email with a link to the malicious host, potentially allowing the attacker to capture the reset token and take over the victim's account.

Vendor
Coollabs
Product
Coolify
CVSS
HIGH 8.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-05
Original CVE updated
2026-09-30
Advisory published
2026-01-05
Advisory updated
2026-09-30

Who should care

Defenders responsible for Coolify deployments, especially those using versions up to and including v4.0.0-beta.434, should assess exposure and prioritize verification and mitigation efforts.

Why it matters

Defenders should care about CVE-2025-64425 because it allows attackers to potentially take over accounts through manipulated password reset links in Coolify deployments. Roles responsible for Coolify deployments, especially those using vulnerable versions, should assess exposure and prioritize verification and mitigation efforts.

  • Potential account takeover through password reset manipulation
  • Exposure of sensitive authentication information
  • Need for verification of affected versions and deployments
  • Priority for patching or applying compensating controls

Technical summary

The vulnerability allows an attacker to initiate a password reset for a victim and modify the host header of the request to a malicious value, potentially leading to account takeover. This issue affects Coolify versions up to and including v4.0.0-beta.434. An attacker can exploit this by sending a password reset request with a modified host header, causing the victim to receive a password reset email with a link to the malicious host. If the victim clicks this link, their reset token is sent to the attacker's server, allowing the attacker to use it to change the victim's password and take over their account.

Defensive priority

Defenders should prioritize verifying exposure in their Coolify deployments, especially those using versions up to and including v4.0.0-beta.434, and assess the feasibility of compensating controls until an official patch is available.

Recommended defensive actions

  • Verify exposure in Coolify deployments, especially those using versions up to and including v4.0.0-beta.434
  • Assess the feasibility of compensating controls until an official patch is available
  • Monitor for suspicious password reset activity
  • Consider implementing additional security measures for authentication and account management
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The vulnerability is described in the CVE Program record and the NVD vulnerability detail page. The source reference provides additional information from the vendor's advisory. However, details about the exploit and affected scope are limited. Defenders should verify exposure in their Coolify deployments, especially those using versions up to and including v4.0.0-beta.434, and assess the feasibility of compensating controls until an official patch is available. The vendor's advisory and CVE record provide the most authoritative and up

Sources and references

Verified primary and authoritative sources

  • CVE-2025-64425 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-64425

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-64425 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64425

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coollabsio/coolify/security/advisories/GHSA-f737-2p93-g2cw

    [email protected] - Exploit, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.