Impact
The upload endpoint for database backup restores in Coolify does not enforce file type or size validation prior to version 4.0.0‑beta.474, allowing an authenticated user to upload unexpected or oversized files that could affect service availability. The flaw corresponds to CWE‑434 and CWE‑770 weaknesses.
Affected Systems
The vulnerability affects deployments of Coolify earlier than version 4.0.0‑beta.474. Any installation running one of those releases with the backup restore feature enabled is susceptible to the issue.
Risk and Exploitability
The CVSS score of 3.1 places the risk in a low severity range and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires legitimate authentication to the application, and the impact is limited to service disruption rather than data compromise or privilege escalation.
OpenCVE Enrichment