CVE-2026-55079
published 2026-07-08CVE-2026-55079: Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.61%
47.9th percentile
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `FileSize` against an upper bound (`MaxFileSize = 100 MiB`) before allocation. As a workaround, restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.24.0 < 2.29.17 | 2.29.17 |
| coder | coder | >= 2.30.0 < 2.32.7 | 2.32.7 |
| coder | coder | >= 2.33.0 < 2.33.8 | 2.33.8 |
| coder | coder | >= 2.34.0 < 2.34.2 | 2.34.2 |
| github.com | coder_coder_v2 | >= 2.24.0 < 2.29.17 | 2.29.17 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.32.7 | 2.32.7 |
| github.com | coder_coder_v2 | >= 2.33.0 < 2.33.8 | 2.33.8 |
| github.com | coder_coder_v2 | >= 2.34.0 < 2.34.2 | 2.34.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Data Upload dataupload.go NewDataBuilder FileSize unrestricted upload
vuldb·2026-07-08·CVSS 4.9
CVE-2026-55079 [MEDIUM] Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Data Upload dataupload.go NewDataBuilder FileSize unrestricted upload
A vulnerability marked as critical has been reported in Coder up to 2.29.16/2.32.6/2.33.7/2.34.1. This impacts the function NewDataBuilder of the file provisionersdk/proto/dataupload.go of the component Data Upload Handler. Performing a manipulation of the argument FileSize results in unrestricted upload.
This vulnerability is reported as CVE-2026-55079. The attack is possible to be carried out remotely. No exploit exists.
GHSA
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
ghsa·2026-07-06
CVE-2026-55079 [MEDIUM] CWE-789 Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
### Summary
`NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained
### Impact
An authenticated user able to reach the provisioner daemon serve endpoint could send a roughly 50-byte message declaring a huge `FileSize` (for example 1 TiB), triggering an unrecoverable Go out-of-memory abort that terminates `coderd`. This is a single-message denial of service affecting the entire deployment.
### Patches
The fix validates `FileSize` against an upper bound (`MaxFileSize = 100 MiB`) before
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/pull/25710https://github.com/coder/coder/releases/tag/v2.29.17https://github.com/coder/coder/releases/tag/v2.32.7https://github.com/coder/coder/releases/tag/v2.33.8https://github.com/coder/coder/releases/tag/v2.34.2https://github.com/coder/coder/security/advisories/GHSA-f962-qm93-mj4c
2026-07-08
Published