Coolify Patches Password Reset Poisoning Flaw That Could Redirect Tokens to Attackers
A vulnerability in Coolify, an open-source deployment platform, allowed attackers to manipulate password reset links by injecting a forged 'x-forwarded-host' header into requests. Because the application derived the reset URL destination from untrusted request metadata rather than a fixed configuration value, a crafted header could redirect the reset token to an attacker-controlled server. The flaw involved a host-validation cache bug that skipped validation on an empty cache, enabling the malicious header to influence the generated link. Exploitation required the forged header to reach the application and the victim to click the link, meaning it was not an automatic or universal compromise. Coolify credited security researcher bugbunny.ai for the report and released a patch in version v4.0.0-beta.471.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in