CVE-2026-34198
Last modified
CVE-2026-34198 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), accepting X-Forwarded-Host from any source. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the TrustProxies middleware trusts all proxies ($proxies = '*'), accepting X-Forwarded-Host from any source. The TrustHosts middleware, intended to prevent host header attacks, has a circular caching dependency that prevents it from ever validating hosts. When a password reset is requested, the ResetPassword notification generates the reset URL using url(route(..., false)), which derives the host from the (spoofable) request. An unauthenticated attacker can trigger a password reset email containing a link pointing to an attacker-controlled domain, enabling token theft and account takeover. This issue is fixed in version 4.0.0-beta.471.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| coollabsio | coolify | < 4.0.0-beta.471 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-34198?
How severe is CVE-2026-34198?
How do I fix CVE-2026-34198?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34192Software installed and run as a non-privileged user may cond…7.7
- CVE-2026-34193Kernel software installed and running inside a Guest/Host VM…4.3
- CVE-2026-34194Software installed and run as a non-privileged user may cond…7.1
- CVE-2026-34195Software installed and run as a non-privileged user may cond…8.8
- CVE-2026-34196Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-34197Improper Input Validation, Improper Control of Generation of…8.8
- CVE-2026-34200Nhost is an open source Firebase alternative with GraphQL. P…7.5
- CVE-2026-34202ZEBRA is a Zcash node written entirely in Rust. Prior to zeb…7.5
- CVE-2026-34203Nautobot is a Network Source of Truth and Network Automation…4.3
- CVE-2026-34204MinIO is a high-performance object storage system. Prior to …7.1
- CVE-2026-34205Home Assistant is open source home automation software that …9.6
- CVE-2026-34206Captcha Protect is a Traefik middleware to add an anti-bot c…6.1
Are you affected by CVE-2026-34198?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
