Follow us
Breaking
Web Hosting

Coolify growth risks in the 2026 PaaS market

Coolify faces significant challenges including 11 major security vulnerabilities with CVSS 10.0 scores and high resource overhead. Compared to Dokploy, which uses only 350MB of RAM at idle, Coolify requires up to 1.2GB, impacting VPS-native developers.

Share

Security vulnerabilities and resource overhead

In May 2026, researchers disclosed 11 major security vulnerabilities in the Coolify codebase. These flaws came from two independent research efforts. Three of these vulnerabilities, including CVE-2025-22612 and CVE-2025-22609, received CVSS 10.0 scores. They allowed command injection. Attackers could bypass authentication to gain full control of managed servers. Researchers reported 52,890 exposed Coolify instances globally at the time of the disclosure. The 11 major vulnerabilities disclosed in May 2026 included command injection and root key exposure, forcing many users to manually pull updated images and restart their entire Coolify stack to protect their data.

The platform’s resource appetite creates risks for VPS users. Coolify uses between 500MB and 1.2GB of RAM at idle. This usage increases when users enable monitoring features. The CPU consumption also idles at 5% to 7% and spikes to 25% when the built-in metrics collection runs. Dokploy uses only 350MB of RAM and less than 1% CPU at idle. This difference matters for developers on a 4GB VPS. The resource gap is real.

Security gaps exist.

The vulnerabilities in early 2026 targeted core functionality like database backups and SSH key management. These were not edge-case features. One vulnerability, CVE-2025-22611, allowed privilege escalation to full administrative control. Another, CVE-2025-64419, enabled command injection via Docker Compose configuration. These flaws require immediate patching for all users.

Scaling limits and architecture

Coolify manages multiple servers independently from a single dashboard. It does not provide native clustering or automatic load balancing between nodes. Users must configure routing manually with Nginx or Traefik. Dokploy and CapRover both use Docker Swarm to handle service scheduling and networking across multiple nodes. This allows for automatic failover and load distribution. CapRover has been around since 2017 and uses Docker Swarm. Dokploy is newer and reached 36,000 stars in April 2026. Its TypeScript and Next.js codebase is easier to read for modern developers.

Scaling remains manual.

Dokploy and Coolify both support Docker Compose for multi-service stacks. CapRover has limited Docker Compose support. This limitation makes complex, multi-container applications difficult to manage in CapRover. Dokku remains a single-server tool that uses the command line for all operations. Dokku has 32,000 stars and provides Heroku-style buildpack support. Dokku is a low-resource option that runs on a $5 VPS with 1GB RAM.

Dokploy provides native multi-node support through its architecture. This makes it a top choice for small teams that need cheap clustering. It handles service replicas and rolling deploys natively. CapRover offers stability due to its long history. It provides a large library of one-click app templates. However, the development pace for CapRover has slowed compared to Coolify and Dokploy.

Will the v5 rewrite resolve these architectural gaps?

You know that infrastructure stability matters.

Licensing and observability costs

Coolify uses an Apache 2.0 license for its entire codebase. This allows commercial use without restrictions. Dokploy uses a different model where content in the proprietary directory falls under the Dokploy Source Available License. This requires a separate commercial agreement for distribution.

Platform GitHub Stars License Idle RAM
Coolify 60,955 Apache 2.0 500-1200MB
Dokploy 36,826 Apache 2.0 + DSAL 350MB
CapRover 15,139 Apache 2.0 300-400MB
Dokku 32,111 MIT Low

The total cost of a production stack includes observability. Coolify does not include web analytics, error tracking, session replay, or uptime monitoring. Developers must pay for third-party tools to get these features. Adding Sentry at $26, Plausible at $9, FullStory at $199, and Better Uptime at $15 creates a monthly bill of $240. Temps provides all four of these features in a single, free, self-hosted Rust binary.

Coolify Cloud users pay $5 per month for two connected servers. Additional servers cost $3 per month each. This managed version does not provide the same level of data sovereignty as self-hosting. You must also account for the time spent on manual updates and security hardening.

Share

Technewsdaily

Senior tech writer covering AI, gadgets and cybersecurity. Breaking down the news that matters, every day.