CVE-2025-64422 - Rate-limit bypass on login via X-Forwarded-Host header - 2025 Update

CVE-2025-64422 - Rate-limit bypass on login via X-Forwarded-Host header - 2025 Update

CVE ID : CVE-2025-64422 Published : Jan. 5, 2026, 8:29 p.m. | 42 minutes ago Description : Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify vstarting with version 4.0.0-beta.434, the /login endpoint advertises a rate limit of 5 requests but can be trivially bypassed by rotating the X-Forwarded-For header. This enables unlimited credential stuffing and brute-force attempts against user and admin accounts. As of time of publication, it is unclear if a patch is available. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
Jan. 5, 2026

Source: Telegram CVE Monitor