cbcvebase.
CVE-2026-55078
published 2026-07-07

CVE-2026-55078: Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8…

PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.60%
47.5th percentile
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZip`, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer. Exploitation requires authenticated file-upload access and the impact is limited to availability (denial of service). The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds a metadata preflight check that sums projected entry sizes and a streaming writer that enforces the aggregate limit during decompression. As a workaround, restrict file-upload permissions to trusted users or place a reverse proxy with request-body size limits in front of `coderd`.

Affected

12 ranges
VendorProductVersion rangeFixed in
codercoder——
codercoder——
codercoder——
codercoder——
codercoder>= 2.17.0 < 2.29.172.29.17
codercoder>= 2.30.0 < 2.32.72.32.7
codercoder>= 2.33.0 < 2.33.82.33.8
codercoder>= 2.34.0 < 2.34.22.34.2
github.comcoder_coder_v2>= 2.17.0 < 2.29.172.29.17
github.comcoder_coder_v2>= 2.30.0 < 2.32.72.32.7
github.comcoder_coder_v2>= 2.33.0 < 2.33.82.33.8
github.comcoder_coder_v2>= 2.34.0 < 2.34.22.34.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.