Description
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `FileSize` against an upper bound (`MaxFileSize = 100 MiB`) before allocation. As a workaround, restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.
Published: 2026-07-07
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Coder’s provisioner component creates a byte slice whose size is taken directly from a client‑supplied File. Because the field is not bounded, an attacker who can submit an upload can force the server to allocate an arbitrarily large buffer, bypassing the protocol’s 4 MiB wire limit. The allocation can exhaust memory or trigger a crash, producing a denial of service for the provisioner daemon and any environments that rely on it.

Affected Systems

Affected versions include Coder releases from 2.24.0 to 2.29.6, from 2.32.0 to 2.32.6, from 2.33.0 to 2.33.7, and from 2.34.0 to 2.34.1. The issue was resolved in releases 2.29.7, 2.32.7, 2.33.8, and 2.34.2, which enforce a maximum FileSize of 100 MiB before allocating memory.

Risk and Exploitability

The CVSS score of 4.9 rates the vulnerability as moderate, but the EPSS score of less than 1% indicates the risk of exploitation is currently low. The flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with permission to upload files through the provisioner daemon serve endpoint. By sending a payload with a large FileSize value, an attacker can provoke an out‑of‑memory condition that kills or stalls the daemon, limiting service availability. The threat is confined to deployments where such uploads are authorized and where the daemon has not been updated to the fixed releases.

Generated by OpenCVE AI on July 26, 2026 at 18:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Coder to version 2.29.7 or later (including 2.32.7, 2.33.8, or 2.34.2) to apply the FileSize bound check.
  • Restrict the provisioner daemon serve endpoint so submit upload requests.
  • Enforce a maximum upload size on the client or network layer to prevent large FileSize values before they reach the backend.

Generated by OpenCVE AI on July 26, 2026 at 18:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f962-qm93-mj4c Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
History

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Coder
Coder coder
Vendors & Products Coder
Coder coder

Wed, 08 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Description Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates `FileSize` against an upper bound (`MaxFileSize = 100 MiB`) before allocation. As a workaround, restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.
Title Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-08T12:53:41.432Z

Reserved: 2026-06-16T14:33:35.711Z

Link: CVE-2026-55079

cve-icon Vulnrichment

Updated: 2026-07-08T12:53:32.877Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:00:02Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value