CVE-2025-64420HIGH 8.8EPSS p38.5%

CVE-2025-64420CVE-2025-64420

Description

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the Coolify instance. This allows them to ssh to the server and authenticate as root user, using the private key. As of time of publication, it is unclear if a patch is available.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.50% probability of exploitation · percentile 38.5% · 2026-06-18T12:00:27Z
Published2026-01-05
Last modified2026-01-12

Underlying weaknesses· 1

CWE-522

References

  1. https://github.com/coollabsio/coolify/security/advisories/GHSA-qwxj-qch7-whpc

1

TypeTargetConfidenceTier
WeaknessInsufficiently Protected Credentialscwe-5220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-22612
CVE
CVE-2025-22609
CVE
CVE-2025-64424
CVE
CVE-2025-66212
CVE
CVE-2025-64423
CVE
CVE-2025-66210
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.