VulnSea

coder has 26 CVEs on record between 2024 and 2026. Disclosure cadence is accelerating: 25 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 20. The median CVSS is 7.2 (high). None have a confirmed exploitation report. The most common weakness class is CWE-863 (4). Most affected products: github.com/coder/coder/v2 (22), github.com/coder/coder (3), coder (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.2
Publish → KEV
Last 90 days
25 prev 0

Products

  • github.com/coder/coder/v2 22
  • github.com/coder/coder 3
  • coder 1
26
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

coder vulnerabilities

CVEs affecting coder, newest first. Open any entry for full detail, references, and exploit status.

26 CVEsRSS

CVE-2026-63443High· 8.3
6d ago

Coder allows organizations to provision remote development environments via Terraform

Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected…

Twilightcoder · coderEPSS 0.42%via NVD
GO-2026-6267None
3w ago

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder

Sunlitcoder · github.com/coder/codervia OSV
GO-2026-6265None
3w ago

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder

Sunlitcoder · github.com/coder/codervia OSV
GHSA-8fxq-53rx-ph5fLow· 3.7
1mo ago

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison

Sunlitcoder · github.com/coder/coder/v2via GHSA
GHSA-h58c-xccx-75m3Low· 3.4
1mo ago

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings

Sunlitcoder · github.com/coder/coder/v2via GHSA
GO-2026-5923None
2mo ago

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write in github.com/coder/coder

Sunlitcoder · github.com/coder/codervia OSV
GHSA-qrwj-vh9x-gw5vHigh· 8.3
2mo ago

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Coder's workspace agent API insecure redirect handling allowed cross-agent file read and write

Twilightcoder · github.com/coder/coder/v2via GHSA
CVE-2026-55076High· 7.4
2mo ago

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

Twilightcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-55075High· 7.4
2mo ago

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Twilightcoder · github.com/coder/coder/v2EPSS 0.48%via GHSA
CVE-2026-55077High· 7.2
2mo ago

Coder: User-admin role can reset owner account password

Coder: User-admin role can reset owner account password

Twilightcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-55427High· 8.3
2mo ago

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Twilightcoder · github.com/coder/coder/v2EPSS 0.47%via GHSA
CVE-2026-55079Medium· 4.9
2mo ago

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

Sunlitcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-55429High· 8.7
2mo ago

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Twilightcoder · github.com/coder/coder/v2EPSS 0.51%via GHSA
CVE-2026-55428High· 8.2
2mo ago

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Twilightcoder · github.com/coder/coder/v2EPSS 0.40%via GHSA
CVE-2026-55430Medium· 5.8
2mo ago

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

Sunlitcoder · github.com/coder/coder/v2EPSS 0.21%via GHSA
CVE-2026-55078Medium· 6.5
2mo ago

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

Sunlitcoder · github.com/coder/coder/v2EPSS 0.60%via GHSA
CVE-2026-55431High· 7.7
2mo ago

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Twilightcoder · github.com/coder/coder/v2EPSS 0.34%via GHSA
CVE-2026-55432Medium· 5.4
2mo ago

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55433Medium· 5.4
2mo ago

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

Sunlitcoder · github.com/coder/coder/v2EPSS 0.39%via GHSA
CVE-2026-55434Medium· 6.5
2mo ago

Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

Sunlitcoder · github.com/coder/coder/v2EPSS 0.55%via GHSA
CVE-2026-55435Medium· 5.4
2mo ago

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55436High· 7.4
2mo ago

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Twilightcoder · github.com/coder/coder/v2EPSS 0.26%via GHSA
CVE-2026-55437Medium· 5.4
2mo ago

Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component

Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component

Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55438Medium· 5.8
2mo ago

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

Sunlitcoder · github.com/coder/coder/v2EPSS 0.22%via GHSA
CVE-2026-44454High· 8.1
2mo ago

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

Twilightcoder · github.com/coder/coder/v2EPSS 2.6%via GHSA
CVE-2024-27918High· 8.2
2y ago

Coder's OIDC authentication allows email with partially matching domain to register

Coder's OIDC authentication allows email with partially matching domain to register

Twilightcoder · github.com/coder/coder/v2EPSS 0.97%via OSV
coder vulnerabilities (CVEs) · VulnSea