CVE-2026-55079: Coder

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `FileSize` against an upper bound (`MaxFileSize = 100 MiB`) before allocation. As a workaround, restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.

Affected products

  • Coder Coder: from 2.24.0, before 2.29.17 (fixed in 2.29.17); from 2.30.0, before 2.32.7 (fixed in 2.32.7); from 2.33.0, before 2.33.8 (fixed in 2.33.8); from 2.34.0, before 2.34.2 (fixed in 2.34.2)

Published 2026-07-08. Last modified 2026-07-08.