CVE-2026-100746 Overview
CVE-2026-100746 is a missing authentication vulnerability [CWE-287] in coollabsio Coolify versions up to 4.1.0. The flaw resides in the Github::redirect function within /webhooks/source/github/redirect, part of the GitHub App Setup Handler component. Attackers can manipulate the state argument to bypass authentication checks remotely. A public exploit exists, and the issue is resolved in version 4.1.1 via commit fc89e357feed5180ed1ab5eb9cb330578f025539.
Critical Impact
Remote, unauthenticated attackers can abuse the GitHub App redirect flow to overwrite application secrets, enabling unauthorized integration takeover of self-hosted Coolify deployments.
Affected Products
- coollabsio Coolify versions up to and including 4.1.0
- Coolify GitHub App Setup Handler component (Github::redirect function)
- Self-hosted Coolify instances exposing the /webhooks/source/github/redirect endpoint
Discovery Timeline
- 2026-09-27 - CVE-2026-100746 published to the National Vulnerability Database
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-100746
Vulnerability Analysis
The vulnerability affects the GitHub App setup redirect handler used when installing or configuring a GitHub App integration in Coolify. During normal operation, GitHub redirects the user back to Coolify with a state parameter and installation data. The Github::redirect function processes this callback and persists integration secrets without verifying that the request originated from an authenticated administrative session.
Because the state parameter is not cryptographically bound to a server-side session, a remote attacker can craft a request to /webhooks/source/github/redirect and influence which GitHub App record is updated. The public proof-of-concept, published in a CVE Discovery repository, demonstrates unauthenticated overwrite of GitHub App secrets.
Root Cause
The root cause is missing authentication on a state-changing endpoint [CWE-287]. The handler trusts the inbound state value rather than validating it against a signed, session-bound token. The upstream patch introduces Illuminate\Support\Facades\Cache and Illuminate\Support\Str to generate and verify a server-side manifestState nonce before accepting the callback.
Attack Vector
Exploitation requires only network reachability to the Coolify web interface. No credentials, user interaction, or elevated privileges are needed. An attacker who successfully overwrites GitHub App credentials can intercept subsequent webhook events, poison source control integrations, and influence deployment pipelines managed by Coolify.
use App\Models\PrivateKey;
use App\Rules\SafeExternalUrl;
use Illuminate\Foundation\Auth\Access\AuthorizesRequests;
+use Illuminate\Support\Facades\Cache;
use Illuminate\Support\Facades\Http;
+use Illuminate\Support\Str;
use Lcobucci\JWT\Configuration;
use Lcobucci\JWT\Signer\Key\InMemory;
use Lcobucci\JWT\Signer\Rsa\Sha256;
Source: GitHub Commit fc89e357 — app/Livewire/Source/Github/Change.php. The patch adds cache-backed state validation to bind the GitHub App setup flow to a server-generated nonce.
function createGithubApp(webhook_endpoint, preview_deployment_permissions, administration) {
const {
organization,
- uuid,
- html_url
+ html_url,
+ uuid
} = @json($github_app);
if (!webhook_endpoint) {
alert('Please select a webhook endpoint.');
return;
}
let baseUrl = webhook_endpoint;
const name = @js($name);
+ const manifestState = @js($manifestState);
const isDev = @js(config('app.env')) ===
'local';
const devWebhook = @js(config('constants.webhooks.dev_webhook'));
Source: GitHub Commit fc89e357 — change.blade.php. The front-end now passes a server-issued manifestState to GitHub, which the backend validates on return.
Detection Methods for CVE-2026-100746
Indicators of Compromise
- Unauthenticated HTTP requests to /webhooks/source/github/redirect originating from unexpected source IPs
- Unexpected modifications to GitHub App records, including changes to client_secret, webhook_secret, or private key fields
- GitHub App installation events in Coolify that do not correlate with an administrator session in access logs
Detection Strategies
- Review Coolify web server access logs for requests to the /webhooks/source/github/* path tree that lack a prior authenticated administrative session
- Audit the Coolify database for recent updates to GitHub source integrations and compare against known administrator activity
- Compare the deployed Coolify version against the fixed release by inspecting the running container image tag or git revision
Monitoring Recommendations
- Alert on any writes to GitHub App credential fields outside of scheduled maintenance windows
- Forward Coolify application and web logs to a central analytics platform and build detections for anonymous access to webhook setup endpoints
- Monitor outbound traffic from Coolify to GitHub for unexpected App installation callbacks
How to Mitigate CVE-2026-100746
Immediate Actions Required
- Upgrade Coolify to version 4.1.1 or later, which includes commit fc89e357feed5180ed1ab5eb9cb330578f025539
- Rotate all GitHub App client secrets, webhook secrets, and private keys associated with Coolify integrations after upgrading
- Restrict network exposure of the Coolify management interface to trusted administrator networks or a VPN
Patch Information
The fix is included in Coolify release v4.1.1 and merged via Pull Request #10362. The commit introduces a cache-backed manifestState nonce that binds the GitHub App setup redirect to a server-side session, enforcing authentication on the Github::redirect handler. See the VulDB entry for CVE-2026-100746 for additional metadata.
Workarounds
- Place the Coolify instance behind a reverse proxy that enforces authentication or IP allowlisting on /webhooks/source/github/* paths until the upgrade is applied
- Temporarily disable the GitHub App source integration and reconfigure it only from a trusted administrative network after patching
- Monitor and manually review GitHub App configuration changes until the patched version is deployed
# Upgrade Coolify to the patched release
cd /data/coolify
git fetch --tags
git checkout v4.1.1
./upgrade.sh
# Verify running version
docker inspect coolify --format '{{.Config.Image}}'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.