# CVE-2026-41899

> Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, POST /api/feedback has no authentication, no rate limiting, and no input validation, allowing arbitrary content to be forwarded directly to a Discord webhook and enabling spam, content injection, and webhook abuse. This issue is fixed in version 4.0.0-beta.474.

- **CVSS:** 6.5 (MEDIUM)
- **EPSS:** 0.3%
- **CWE:** CWE-306, CWE-770

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-41899
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
