CVE Browser

Page 1 (more results available)

Vendor: Coder Remove filter Clear all
CVE-2026-63443 HIGH

Coder: Workspace agent API insecure redirect handling allowed cross-agent file read and write

CVSS 8.3 EPSS 0.76% Sep 15, 2026
Go
CVE-2026-55438 MEDIUM

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

CVSS 6.8 EPSS 0.22% Jul 8, 2026
Go
CVE-2026-55437 MEDIUM

Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component

CVSS 5.4 EPSS 0.32% Jul 8, 2026
Go
CVE-2026-55436 HIGH

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

CVSS 7.4 EPSS 0.26% Jul 8, 2026
Go
CVE-2026-55433 MEDIUM

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

CVSS 5.4 EPSS 0.39% Jul 8, 2026
Go
CVE-2026-55432 MEDIUM

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

CVSS 5.4 EPSS 0.32% Jul 8, 2026
Go
CVE-2026-55431 HIGH

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

CVSS 7.7 EPSS 0.34% Jul 8, 2026
Go
CVE-2026-55430 MEDIUM

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

CVSS 6.8 EPSS 0.21% Jul 8, 2026
Go
CVE-2026-55429 HIGH

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

CVSS 8.7 EPSS 0.51% Jul 8, 2026
Go
CVE-2026-55428 HIGH

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

CVSS 8.2 EPSS 0.40% Jul 7, 2026
Go
CVE-2026-55427 HIGH

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

CVSS 8.3 EPSS 0.47% Jul 7, 2026
Go
CVE-2026-55079 MEDIUM

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

CVSS 6.5 EPSS 0.61% Jul 7, 2026
Go
CVE-2026-55078 MEDIUM

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

CVSS 6.5 EPSS 0.60% Jul 7, 2026
Go
CVE-2026-55077 HIGH

Coder: User-admin role can reset owner account password

CVSS 7.2 EPSS 0.61% Jul 7, 2026
Go
CVE-2026-55076 HIGH

Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking

CVSS 7.4 EPSS 0.61% Jul 7, 2026
Go
CVE-2026-55075 HIGH

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

CVSS 7.4 EPSS 0.48% Jul 7, 2026
Go
CVE-2026-46354 CRITICAL

Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft

CVSS 9.1 EPSS 0.32% Jul 7, 2026
Go
CVE-2026-45796 MEDIUM

Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint

CVSS 6.5 EPSS 0.43% Jul 7, 2026
Go
CVE-2026-44454 HIGH

Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent

CVSS 8.8 EPSS 2.64% Jul 7, 2026
Go
CVE-2026-55434 MEDIUM

Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

CVSS 6.5 EPSS 0.55% Jul 7, 2026
Go
CVE-2026-55435 MEDIUM

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

CVSS 5.4 EPSS 0.32% Jul 7, 2026
Go
CVE-2026-35454 HIGH

Code Extension Marketplace has a Zip Slip Path Traversal

CVSS 8.7 EPSS 0.43% Apr 6, 2026
Go
CVE-2025-66411 HIGH

Coder logged sensitive objects unsanitized

CVSS 7.8 EPSS 0.23% Dec 3, 2025
Go
CVE-2025-59956 MEDIUM

AgentAPI exposed user chat history via a DNS rebinding attack

CVSS 6.5 EPSS 0.43% Sep 29, 2025
Go
CVE-2025-58437 HIGH

Coder's privilege escalation vulnerability could lead to a cross workspace compromise

CVSS 8.1 EPSS 0.38% Sep 6, 2025
Go

Showing 1 to 25 CVEs · page 1 (more available)