6.5

CVE-2026-55079

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `FileSize` against an upper bound (`MaxFileSize = 100 MiB`) before allocation. As a workaround, restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CoderCoder SwPlatformgo Version >= 2.24.0 < 2.29.17
CoderCoder SwPlatformgo Version >= 2.30.0 < 2.32.7
CoderCoder SwPlatformgo Version >= 2.33.0 < 2.33.8
CoderCoder SwPlatformgo Version >= 2.34.0 < 2.34.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.26
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
security-advisories@github.com 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

https://github.com/coder/coder/releases/tag/v2.32.7
Release Notes
https://github.com/coder/coder/releases/tag/v2.33.8
Release Notes
https://github.com/coder/coder/releases/tag/v2.34.2
Release Notes
https://github.com/coder/coder/releases/tag/v2.29.17
Release Notes
https://github.com/coder/coder/security/advisories/GHSA-f962-qm93-mj4c
Patch
Vendor Advisory
https://github.com/coder/coder/pull/25710
Patch
Issue Tracking