Executive brief
Coder, a platform used to manage remote development environments, is vulnerable to a denial-of-service attack. An attacker with high-level permissions could send a specially crafted message that forces the system to attempt an impossible memory allocation, causing the entire Coder service to crash. This could disrupt development operations and prevent teams from accessing their remote workspaces.
Technical details
A vulnerability exists in Coder's `provisionersdk/proto/dataupload.go` within the `NewDataBuilder` function. The component fails to validate the `FileSize` field in a `DataUpload` message before using it to allocate a byte slice. While the DRPC wire limit is 4 MiB, the integer value for `FileSize` was unconstrained, allowing an attacker to request massive allocations (e.g., 1 TiB) that trigger an unrecoverable `runtime.throw` and crash the `coderd` process. This requires high privileges to exploit. The issue is fixed in versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2 by implementing a `MaxFileSize` limit of 100 MiB.
Affected products
- Coder Coder >= 2.24.0, < 2.29.17; >= 2.30.0, < 2.32.7; >= 2.33.0, < 2.33.8; >= 2.34.0, < 2.34.2
Timeline
- 2026-05-27: patched: Fix merged into main branch via PR #25710
- 2026-06-11: advisory: Security releases v2.32.7 and v2.33.8 published
- 2026-06-12: advisory: Security release v2.29.17 published
- 2026-07-08: disclosed: CVE-2026-55079 published to NVD
References
- https://github.com/coder/coder/pull/25710
- https://github.com/coder/coder/releases/tag/v2.29.17
- https://github.com/coder/coder/releases/tag/v2.32.7
- https://github.com/coder/coder/releases/tag/v2.33.8
- https://github.com/coder/coder/releases/tag/v2.34.2
- https://github.com/coder/coder/security/advisories/GHSA-f962-qm93-mj4c