{"id":"CVE-2025-64422","summary":"Rate-limit bypass on login via X-Forwarded-Host header","details":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimited credential stuffing and brute-force attempts against user and admin accounts. As of time of publication, it is unclear if a patch is available.","aliases":["GHSA-688j-rm43-5r8x"],"modified":"2026-08-12T03:51:33.397764415Z","published":"2026-01-05T20:29:34.750Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64422.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64422.json"},{"type":"ADVISORY","url":"https://github.com/coollabsio/coolify/security/advisories/GHSA-688j-rm43-5r8x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64422"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/coollabsio/coolify","events":[{"introduced":"b474eb411da779bb9be5a028e68351b15c558517"},{"fixed":"96bfc14543c893f0b0156b12c40250d3f8cc96a2"}],"database_specific":{"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:coollabs:coolify:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"\u003e= 4.0.0-beta.434"},{"last_affected":"\u003e= 4.0.0-beta.434"},{"introduced":"0"},{"fixed":"4.0.0"}]}}],"versions":["\u003e= 4.0.0-beta.434","v4.0.0-beta.474","v4.0.0-beta.473","v4.0.0-beta.472","v4.0.0-beta.471","v4.0.0-beta.470","v4.0.0-beta.469","v4.0.0-beta.468","v4.0.0-beta.467","v4.0.0-beta.466","v4.0.0-beta.465","v4.0.0-beta.464","v4.0.0-beta.463","v4.0.0-beta.462","v4.0.0-beta.461","v4.0.0-beta.460","v4.0.0-beta.459","v4.0.0-beta.458","v4.0.0-beta.457","v4.0.0-beta.456","v4.0.0-beta.452","v4.0.0-beta.455","v4.0.0-beta.453","v4.0.0-beta.454","v4.0.0-beta.450","v4.0.0-beta.451","v4.0.0-beta.449","v4.0.0-beta.448","v4.0.0-beta.447","v4.0.0-beta.446","v4.0.0-beta.445","v4.0.0-beta.444","v4.0.0-beta.443","v4.0.0-beta.442","v4.0.0-beta.441","v4.0.0-beta.440","v4.0.0-beta.439","v4.0.0-beta.438","v4.0.0-beta.437","v4.0.0-beta.435","v4.0.0-beta.436","v4.0.0-beta.434"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64422.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}