CVE-2026-55079
- EPSS 0.34%
- Veröffentlicht 07.07.2026 23:50:37
- Zuletzt bearbeitet 08.07.2026 19:44:45
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slic...
CVE-2026-55078
- EPSS 0.34%
- Veröffentlicht 07.07.2026 22:47:07
- Zuletzt bearbeitet 08.07.2026 19:45:05
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `POST /api/v2/files` converts zip uploads to tar in memory via `CreateTarFromZ...
CVE-2026-55077
- EPSS 0.34%
- Veröffentlicht 07.07.2026 22:44:28
- Zuletzt bearbeitet 09.07.2026 16:16:44
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` endpoint authorized only `ActionUpdatePersonal` and did not prevent a...
CVE-2026-55076
- EPSS 0.31%
- Veröffentlicht 07.07.2026 22:23:26
- Zuletzt bearbeitet 08.07.2026 19:46:04
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_verified` with a direct Go `bool` type assertion. When an IdP returned t...
CVE-2026-55075
- EPSS 0.29%
- Veröffentlicht 07.07.2026 21:33:38
- Zuletzt bearbeitet 08.07.2026 19:46:56
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained into account takeover. Email-based user matching fell back to linking...
CVE-2026-46354
- EPSS 0.26%
- Veröffentlicht 07.07.2026 21:10:01
- Zuletzt bearbeitet 08.07.2026 19:47:02
Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trust...
CVE-2026-45796
- EPSS 0.34%
- Veröffentlicht 07.07.2026 21:03:11
- Zuletzt bearbeitet 08.07.2026 19:47:08
Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azur...
CVE-2026-44454
- EPSS 1.35%
- Veröffentlicht 07.07.2026 20:16:39
- Zuletzt bearbeitet 08.07.2026 19:47:37
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user input to shell commands, allowing arbitrary code execution inside a pro...
CVE-2026-55434
- EPSS 0.31%
- Veröffentlicht 07.07.2026 20:14:00
- Zuletzt bearbeitet 08.07.2026 19:47:17
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.33.0 and prior to versions 2.33.8 and 2.34.2, AI Bridge provider handlers read request bodies with `io.ReadAll` without a maximum size so an ...
CVE-2026-55435
- EPSS 0.2%
- Veröffentlicht 07.07.2026 17:37:31
- Zuletzt bearbeitet 09.07.2026 16:16:44
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via `Server.IsAuthorized` in `coderd/aibridgeds...