Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.24.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, NewDataBuilder in provisionersdk/proto/dataupload.go allocated a byte slice using the client-supplied FileSize from a DataUpload message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the FileSize value itself was unconstrained. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates FileSize against an upper bound (MaxFileSize = 100 MiB) before allocation. As a workaround, restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.
{
"cwe_ids": [
"CWE-789"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55079.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*",
"extracted_events": [
{
"introduced": "2.24.0"
},
{
"fixed": "2.29.17"
},
{
"introduced": "2.30.0"
},
{
"fixed": "2.32.7"
},
{
"introduced": "2.33.0"
},
{
"fixed": "2.33.8"
},
{
"introduced": "2.34.0"
},
{
"fixed": "2.34.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}