CVE-2026-42145

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. This issue is fixed in version 4.0.0-beta.474.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-07 04:17

Updated : 2026-07-09 16:16


NVD link : CVE-2026-42145

Mitre link : CVE-2026-42145

CVE.ORG link : CVE-2026-42145


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-770

Allocation of Resources Without Limits or Throttling