CVE-2026-55078
published 2026-07-07CVE-2026-55078: Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.60%
47.5th percentile
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer. Exploitation requires authenticated file-upload access and the impact is limited to availability (denial of service). The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds a metadata preflight check that sums projected entry sizes and a streaming writer that enforces the aggregate limit during decompression. As a workaround, restrict file-upload permissions to trusted users or place a reverse proxy with request-body size limits in front of `coderd`.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.17.0 < 2.29.17 | 2.29.17 |
| coder | coder | >= 2.30.0 < 2.32.7 | 2.32.7 |
| coder | coder | >= 2.33.0 < 2.33.8 | 2.33.8 |
| coder | coder | >= 2.34.0 < 2.34.2 | 2.34.2 |
| github.com | coder_coder_v2 | >= 2.17.0 < 2.29.17 | 2.29.17 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.32.7 | 2.32.7 |
| github.com | coder_coder_v2 | >= 2.33.0 < 2.33.8 | 2.33.8 |
| github.com | coder_coder_v2 | >= 2.34.0 < 2.34.2 | 2.34.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 File Upload /api/v2/files CreateTarFromZip denial of service
vuldb·2026-07-08·CVSS 6.5
CVE-2026-55078 [MEDIUM] Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 File Upload /api/v2/files CreateTarFromZip denial of service
A vulnerability was found in Coder up to 2.29.16/2.32.6/2.33.7/2.34.1. It has been classified as problematic. This vulnerability affects the function CreateTarFromZip of the file /api/v2/files of the component File Upload Handler. Performing a manipulation results in denial of service.
This vulnerability is identified as CVE-2026-55078. The attack can be initiated remotely. There is not any exploit available.
GHSA
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
ghsa·2026-07-06
CVE-2026-55078 [MEDIUM] CWE-409 Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
### Summary
`POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer.
> **Note:** Exploitation requires authenticated file-upload access and the impact is limited to availability (denial of service).
### Impact
An authenticated user could upload a zip within the 100 MiB upload limit but containing many highly compressible entries whose decompressed size exhausted memory, crashing `coderd` before any RBAC check. Repeated requests could keep the service unavailable. This is a denial of service; it does not allow data disclosure or code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/pull/25877https://github.com/coder/coder/releases/tag/v2.29.17https://github.com/coder/coder/releases/tag/v2.32.7https://github.com/coder/coder/releases/tag/v2.33.8https://github.com/coder/coder/releases/tag/v2.34.2https://github.com/coder/coder/security/advisories/GHSA-2mg2-p7r7-g27f
2026-07-07
Published