medium

CVE-2026-55079

Go · github.com/coder/coder/v2

Summary

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

Severity
medium
CVSS
4.9
EPSS
0.6% (p47)
CWE
CWE-789
Also known as
GHSA-f962-qm93-mj4c
Published
2026-07-06
Updated
2026-07-06

Advisory details

Summary

NewDataBuilder in provisionersdk/proto/dataupload.go allocated a byte slice using the client-supplied FileSize from a DataUpload message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the FileSize value itself was unconstrained

Impact

An authenticated user able to reach the provisioner daemon serve endpoint could send a roughly 50-byte message declaring a huge FileSize (for example 1 TiB), triggering an unrecoverable Go out-of-memory abort that terminates coderd. This is a single-message denial of service affecting the entire deployment.

Patches

The fix validates FileSize against an upper bound (MaxFileSize = 100 MiB) before allocation.

The fix was backported to all supported release lines:

Release line Patched version
2.34 v2.34.2
2.33 v2.33.8
2.32 v2.32.7
2.29 (ESR) v2.29.17

Workarounds

Restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.

Resources

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22442) for independently disclosing this issue!

References

Related advisories

Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.

Check my repo

Summarize with AI

ChatGPTClaudePerplexity

Sources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.