CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-56157

Critical · CVSS 9.8

Dify — Hard-coded / Default Credentials (CWE-798)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-798

Description

Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file included in its source code. NOTE: the Supplier reports that the Docker configuration does not make PostgreSQL (on TCP port 5432) exposed by default in version 1.0.1 or later.

Search profile — drives PoC discovery

Symbols docker-compose.yamlPOSTGRES_USERPOSTGRES_PASSWORDPOSTGRES_DBdb:postgres:TCP port 5432langgenius/dify
Keywords CVE-2025-56157Dify default credentialsDify PostgreSQL hardcoded credentialsDify docker-compose postgres passwordDify 1.5.1 CWE-798langgenius dify postgres exposedDify default postgres username passwordDify hardcoded database credentials PoC
Versions: <= 1.5.1 (PostgreSQL port exposure mitigated from 1.0.1 onward)

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z