cbcvebase.
CVE-2026-55434
published 2026-07-07

CVE-2026-55434: Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI…

PriorityP339medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.55%
45.0th percentile
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory. Exploitation requires authenticated access to the AI Bridge endpoints and the impact is limited to availability (denial of service). Versions 2.33.8 and 2.34.2 patch the issue. No known workarounds are available.

Affected

6 ranges
VendorProductVersion rangeFixed in
codercoder——
codercoder——
codercoder>= 2.33.0 < 2.33.82.33.8
codercoder>= 2.34.0 < 2.34.22.34.2
github.comcoder_coder_v2>= 2.33.0 < 2.33.82.33.8
github.comcoder_coder_v2>= 2.34.0 < 2.34.22.34.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.