coder has 26 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 25 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 20. The median CVSS is 7.2 (high). None have a confirmed exploitation report. The most common weakness class is CWE-863 (4). Most affected products: github.com/coder/coder/v2 (22), github.com/coder/coder (3), coder (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —
- Last 90 days
- 25 prev 0
Products
- github.com/coder/coder/v2 22
- github.com/coder/coder 3
- coder 1
Worst active — by depth score
CVE-2026-55429High· 8.7Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID48CVE-2026-63443High· 8.3Coder allows organizations to provision remote development environments via Terraform46GHSA-qrwj-vh9x-gw5vHigh· 8.3Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write46CVE-2026-55427High· 8.3Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`46CVE-2026-55428High· 8.2Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator45
coder vulnerabilities
CVEs affecting coder, newest first. Open any entry for full detail, references, and exploit status.
26 CVEsRSS
CVE-2026-63443High· 8.3Coder allows organizations to provision remote development environments via Terraform
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected…
GO-2026-6267NoneCoder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
GO-2026-6265NoneCoder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
GHSA-8fxq-53rx-ph5fLow· 3.7Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
GHSA-h58c-xccx-75m3Low· 3.4Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings
GO-2026-5923NoneCoder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder
GHSA-qrwj-vh9x-gw5vHigh· 8.3Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write
CVE-2026-55076High· 7.4Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
CVE-2026-55075High· 7.4Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
CVE-2026-55077High· 7.2Coder: User-admin role can reset owner account password
Coder: User-admin role can reset owner account password
CVE-2026-55427High· 8.3Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
CVE-2026-55079Medium· 4.9Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
CVE-2026-55429High· 8.7Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
CVE-2026-55428High· 8.2Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVE-2026-55430Medium· 5.8Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
CVE-2026-55078Medium· 6.5Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
CVE-2026-55431High· 7.7Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
CVE-2026-55432Medium· 5.4Coder's sub-agent app registration bypasses template port-sharing policy enforcement
Coder's sub-agent app registration bypasses template port-sharing policy enforcement
CVE-2026-55433Medium· 5.4Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
CVE-2026-55434Medium· 6.5Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
CVE-2026-55435Medium· 5.4Suspended Coder users retain access to AI Bridge LLM proxy endpoints
Suspended Coder users retain access to AI Bridge LLM proxy endpoints
CVE-2026-55436High· 7.4Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
CVE-2026-55437Medium· 5.4Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
CVE-2026-55438Medium· 5.8Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
CVE-2026-44454High· 8.1Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
CVE-2024-27918High· 8.2Coder's OIDC authentication allows email with partially matching domain to register
Coder's OIDC authentication allows email with partially matching domain to register