NewDataBuilder in provisionersdk/proto/dataupload.go allocated a byte slice using the client-supplied FileSize from a DataUpload message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the FileSize value itself was unconstrained
An authenticated user able to reach the provisioner daemon serve endpoint could send a roughly 50-byte message declaring a huge FileSize (for example 1 TiB), triggering an unrecoverable Go out-of-memory abort that terminates coderd. This is a single-message denial of service affecting the entire deployment.
The fix validates FileSize against an upper bound (MaxFileSize = 100 MiB) before allocation.
The fix was backported to all supported release lines:
| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 | | 2.29 (ESR) | v2.29.17 |
Restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts.
Coder would like to thank Anthropic's Security Team (ANT-2026-22442) for independently disclosing this issue!
{
"severity": "MODERATE",
"nvd_published_at": null,
"github_reviewed": true,
"cwe_ids": [
"CWE-789"
],
"github_reviewed_at": "2026-07-06T20:54:41Z"
}