chiprook
← Security
SecuritySeptember 30, 2026, 03:34

Coolify flaw let password-reset tokens be redirected to attacker hosts

A Coolify advisory describes a chain of trusted forwarded headers, a host-validation cache bug and a reset URL derived from the request, allowing reset tokens to be sent to an attacker-controlled domain. The issue is patched in v4.0.0-beta.471.

Coolify flaw let password-reset tokens be redirected to attacker hosts
#Coolify
Read next
Security

Default Join Key Let Attackers Mint Admin Tokens on JFrog Artifactory

Security

cPanel flaw lets a hosting account run code as root and take over the server

Security

Linux KVM ARM64 Flaw Lets Guests Read and Write Host Memory

Security

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files