
Two Coolify vulnerabilities disclosed the same day, and both already have public exploits (CVSS 7.3 each). CVE-2026-100744: missing authorization in the route-level middleware lets a remote attacker manipulate resources without permission. Fixed in 4.2.0. CVE-2026-100746: the GitHub App Setup redirect handler skips authentication entirely, letting a remote attacker overwrite GitHub app secrets. Fixed in 4.1.1. Update now, exploit code for both is already out there. Details: http://vulntracker.io/cves/CVE-2026-100744 #Coolify #CVE #InfoSec #CyberSecurity
