Coolify flaw let password-reset tokens be redirected to attacker hosts
A Coolify advisory describes a chain of trusted forwarded headers, a host-validation cache bug and a reset URL derived from the request, allowing reset tokens to be sent to an attacker-controlled domain. The issue is patched in v4.0.0-beta.471.
- Reset link was built from the X-Forwarded-Host header
- Host validation was skipped when the cache was empty
- Attack required a forged header and a recipient click
- Fix shipped in Coolify v4.0.0-beta.471
Read next
Security