SShortSingh.
Back to feed

Coolify Patches Password Reset Poisoning Flaw That Could Redirect Tokens to Attackers

0
·4 views

A vulnerability in Coolify, an open-source deployment platform, allowed attackers to manipulate password reset links by injecting a forged 'x-forwarded-host' header into requests. Because the application derived the reset URL destination from untrusted request metadata rather than a fixed configuration value, a crafted header could redirect the reset token to an attacker-controlled server. The flaw involved a host-validation cache bug that skipped validation on an empty cache, enabling the malicious header to influence the generated link. Exploitation required the forged header to reach the application and the victim to click the link, meaning it was not an automatic or universal compromise. Coolify credited security researcher bugbunny.ai for the report and released a patch in version v4.0.0-beta.471.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

Developer builds 8-agent Python pipeline with Google ADK to expose multi-agent testing gaps

A developer has published an open-source repository called adk-multiagent that assembles eight Python-based AI agents using Google's Agent Development Kit (ADK), a local MCP server, and a mix of hosted and local models. The project was created to study how multi-agent systems fail in subtle ways, such as hallucinated URLs, miscounted characters, or a validator unable to read the previous agent's output. Each agent is isolated in its own folder with a defined responsibility, separating model-level reasoning from code-level enforcement like path restrictions, link verification, and secret detection. The repository includes agents for blogging, SEO, RAG-based retrieval, code review, triage, and link checking, along with offline tests and flow diagrams. The author frames the project less as a showcase of agents collaborating and more as a study in control boundaries and predictable, testable agent behaviour.

0
ProgrammingDEV Community ·

Major Platforms Like Instagram and Reddit Letting Web Clients Fall Behind

Tech giants including Instagram and Reddit are increasingly neglecting their web clients as resources shift toward mobile app development, according to a DEV Community analysis. Instagram's web interface suffers from unresponsive buttons, failed page loads, and video playback glitches linked to unresolved JavaScript issues and poor state management. Reddit's web client frustrates users with broken nested comment navigation and unpredictable scroll resets caused by inadequate DOM manipulation. The neglect disproportionately affects users who depend on web browsers due to device limitations or accessibility needs, risking broader user alienation. Experts argue that companies must reallocate development resources to web client maintenance and establish user feedback loops to prevent these platforms from becoming effectively mobile-only.

0
ProgrammingDEV Community ·

AI Coding Productivity Gains Come With Long-Term Maintenance Trade-Offs

A growing debate in software development questions whether AI truly delivers the 10x or 100x productivity gains widely claimed. One emerging workflow has developers approving AI-generated code without reading or understanding it, prioritising rapid feature releases over code quality. While this approach can accelerate short-term delivery, it creates serious risks when production issues arise and no developer is familiar with the underlying codebase. An alternative approach requires developers to fully review and own AI-generated code, which is slower initially but produces more maintainable and human-readable results. The article argues that unchecked 'vibe coding' over time erodes the original productivity boost, drawing a parallel to early website builders like Dreamweaver that enabled quick starts but made debugging difficult.

0
ProgrammingDEV Community ·

Developer Launches ReleaseReady, a GitHub Repo Scanner for Pre-Release Checks

Independent developer Vijay Sahani has built ReleaseReady, a free tool that scans GitHub repositories to help developers identify potential issues before shipping a project. The scanner checks areas such as security configurations, dependencies, GitHub Actions, README documentation, and potential exposed secrets. Each finding is categorized as PASS, WARNING, FAIL, or INFO, and repositories receive an overall readiness score to highlight areas needing attention. ReleaseReady connects to a user's GitHub account and performs read-only analysis, meaning it inspects code without making any modifications. The tool, built with React, TypeScript, and Node.js and hosted on Vercel, is currently in an early version with features like scan history and GitHub PR checks planned for future updates.