CVE-2026-34170: Coolify: Server-Side Request Forgery via attacker-controlled GitHub App API URL
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, the GithubApp apiurl field is used as the base URL for server-side HTTP requests without allowlisting or private IP blocking, allowing an authenticated user to configure a GitHub App source that causes Coolify to request internal services or cloud metadata endpoints. This issue is reported as fixed in version 4.0.0-beta.471.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Coolifyto a version that resolves this vulnerability.Fixed in 4.0.0-beta.471
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34170?
CVE-2026-34170 has a medium severity rating of 4.3.
What type of vulnerability is CVE-2026-34170?
CVE-2026-34170 is categorized as a Server-Side Request Forgery (SSRF).
How do I fix CVE-2026-34170?
To fix CVE-2026-34170, upgrade to Coolify version 4.0.0-beta.471 or later.
What are the potential impacts of CVE-2026-34170?
CVE-2026-34170 can allow an authenticated user to send requests to any external server, leading to possible data exposure.
Who is affected by CVE-2026-34170?
CVE-2026-34170 affects users of Coolify versions prior to 4.0.0-beta.471.