{"api_version":"1","generated_at":"2026-07-23T13:09:52+00:00","cve":"CVE-2026-42145","urls":{"html":"https://cve.report/CVE-2026-42145","api":"https://cve.report/api/cve/CVE-2026-42145.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-42145","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-42145"},"summary":{"title":"Coolify: File Upload Without Type or Size Validation in Database Backup Restore","description":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. This issue is fixed in version 4.0.0-beta.474.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-07-07 04:17:51","updated_at":"2026-07-09 16:16:41"},"problem_types":["CWE-434","CWE-770","CWE-434 CWE-434: Unrestricted Upload of File with Dangerous Type","CWE-770 CWE-770: Allocation of Resources Without Limits or Throttling"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"3.1","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"3.1","severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":3.1,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}}],"references":[{"url":"https://github.com/coollabsio/coolify/commit/e6a6446daeace2999fb77888a611a3271812911f","name":"https://github.com/coollabsio/coolify/commit/e6a6446daeace2999fb77888a611a3271812911f","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/coollabsio/coolify/security/advisories/GHSA-66gv-g2w9-6wxp","name":"https://github.com/coollabsio/coolify/security/advisories/GHSA-66gv-g2w9-6wxp","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/coollabsio/coolify/pull/9667","name":"https://github.com/coollabsio/coolify/pull/9667","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474","name":"https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-42145","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42145","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"coollabsio","product":"coolify","version":"affected < 4.0.0-beta.474","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"42145","cve":"CVE-2026-42145","epss":"0.002500000","percentile":"0.161960000","score_date":"2026-07-13","updated_at":"2026-07-14 00:13:16"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-42145","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-09T14:21:17.298839Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-07-09T14:43:05.636Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"coolify","vendor":"coollabsio","versions":[{"status":"affected","version":"< 4.0.0-beta.474"}]}],"descriptions":[{"lang":"en","value":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. This issue is fixed in version 4.0.0-beta.474."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":3.1,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-434","description":"CWE-434: Unrestricted Upload of File with Dangerous Type","lang":"en","type":"CWE"}]},{"descriptions":[{"cweId":"CWE-770","description":"CWE-770: Allocation of Resources Without Limits or Throttling","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-07T03:03:58.895Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/coollabsio/coolify/security/advisories/GHSA-66gv-g2w9-6wxp","tags":["x_refsource_CONFIRM"],"url":"https://github.com/coollabsio/coolify/security/advisories/GHSA-66gv-g2w9-6wxp"},{"name":"https://github.com/coollabsio/coolify/pull/9667","tags":["x_refsource_MISC"],"url":"https://github.com/coollabsio/coolify/pull/9667"},{"name":"https://github.com/coollabsio/coolify/commit/e6a6446daeace2999fb77888a611a3271812911f","tags":["x_refsource_MISC"],"url":"https://github.com/coollabsio/coolify/commit/e6a6446daeace2999fb77888a611a3271812911f"},{"name":"https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474","tags":["x_refsource_MISC"],"url":"https://github.com/coollabsio/coolify/releases/tag/v4.0.0-beta.474"}],"source":{"advisory":"GHSA-66gv-g2w9-6wxp","discovery":"UNKNOWN"},"title":"Coolify: File Upload Without Type or Size Validation in Database Backup Restore"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-42145","datePublished":"2026-07-07T03:03:58.895Z","dateReserved":"2026-04-24T17:15:21.834Z","dateUpdated":"2026-07-09T14:43:05.636Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-07 04:17:51","lastModifiedDate":"2026-07-09 16:16:41","problem_types":["CWE-434","CWE-770","CWE-434 CWE-434: Unrestricted Upload of File with Dangerous Type","CWE-770 CWE-770: Allocation of Resources Without Limits or Throttling"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L","baseScore":3.1,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-07-09T14:21:17.298839Z","id":"CVE-2026-42145","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"42145","Ordinal":"1","Title":"Coolify: File Upload Without Type or Size Validation in Database","CVE":"CVE-2026-42145","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"42145","Ordinal":"1","NoteData":"Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the file upload endpoint (app/Http/Controllers/UploadController.php) for database backup restore uploads did not enforce file type or size validation, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. This issue is fixed in version 4.0.0-beta.474.","Type":"Description","Title":"Coolify: File Upload Without Type or Size Validation in Database"}]}}}