github.com/coder/coder vulnerabilities
CVEs whose affected-version data names the github.com/coder/coder package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
GO-2026-6267NoneCoder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
▾ Sunlitcoder · github.com/coder/codervia OSV
GO-2026-6265NoneCoder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
▾ Sunlitcoder · github.com/coder/codervia OSV
GO-2026-5923NoneCoder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
▾ Sunlitcoder · github.com/coder/codervia OSV
CVE-2026-44454High· 8.1Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
▾ Twilightcoder · github.com/coder/coder/v2EPSS 2.6%via GHSA
CVE-2024-27918High· 8.2Coder's OIDC authentication allows email with partially matching domain to register
Coder's OIDC authentication allows email with partially matching domain to register
▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.97%via OSV