Impact
The vulnerability is a server‑side request forgery (CWE‑918) that occurs when Coolify’s S3 storage endpoint validation only checks URL format. During testConnection(), the application makes a server‑side HTTP request to the configured endpoint, which can be pointed to internal or cloud metadata‑service URLs. An authenticated user with storage‑management permissions can exploit this to discover internal resources or retrieve metadata, potentially aiding further attacks.
Affected Systems
The product affected is Coolify from CoollabsIO. Any installation running a version earlier than 4.0. 4.0.0‑beta.474 and newer contain the fix.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker must first authenticate and possess storage‑management rights, but once those prerequisites are met the SSRF can be triggered with relative ease.
OpenCVE Enrichment