github.com/coder/coder/v2 vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-QRWJ-VH9X-GW5VHighgithub.com/coder/coder/v2: Coder's workspace agent API insecure redirect handling allowed cross-agent file read and writeCVE-2026-55438Mediumgithub.com/coder/coder/v2: Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofingCVE-2026-55437Mediumgithub.com/coder/coder/v2: Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine componentCVE-2026-55436Highgithub.com/coder/coder/v2: Coder's AI Bridge Proxy skips TLS certificate verification in default configurationCVE-2026-55435Mediumgithub.com/coder/coder/v2: Suspended Coder users retain access to AI Bridge LLM proxy endpointsCVE-2026-55434Mediumgithub.com/coder/coder/v2: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpointsCVE-2026-55433Mediumgithub.com/coder/coder/v2: Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containersCVE-2026-55432Mediumgithub.com/coder/coder/v2: Coder's sub-agent app registration bypasses template port-sharing policy enforcementCVE-2026-55431Highgithub.com/coder/coder/v2: Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace appsCVE-2026-55078Mediumgithub.com/coder/coder/v2: Coder: Zip upload decompression lacks aggregate size limit, enabling denial of serviceCVE-2026-55430Mediumgithub.com/coder/coder/v2: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data accessCVE-2026-55428Highgithub.com/coder/coder/v2: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinatorCVE-2026-55429Highgithub.com/coder/coder/v2: Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app IDCVE-2026-55079Mediumgithub.com/coder/coder/v2: Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of serviceCVE-2026-55427Highgithub.com/coder/coder/v2: Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`CVE-2026-55077Highgithub.com/coder/coder/v2: Coder: User-admin role can reset owner account passwordCVE-2026-55075Highgithub.com/coder/coder/v2: Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypassCVE-2026-55076Highgithub.com/coder/coder/v2: Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingCVE-2026-44454Highgithub.com/coder/coder/v2: Coder vulnerable to workspace auto-creation via crafted URL parameters without user consentCVE-2026-46354Criticalgithub.com/coder/coder/v2: Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theftCVE-2026-45796Mediumgithub.com/coder/coder/v2: Coder: Unauthenticated SSRF via Azure Instance Identity EndpointCVE-2025-66411Highgithub.com/coder/coder/v2: Coder logs sensitive objects unsanitizedCVE-2025-58437Highgithub.com/coder/coder/v2: Coder vulnerable to privilege escalation could lead to a cross workspace compromiseGHSA-3RW9-WMC8-8948Lowgithub.com/coder/coder/v2: Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh tokenGHSA-WCX9-CCPJ-HX3CMediumgithub.com/coder/coder/v2: Coder vulnerable to post-auth URL redirection to untrusted site ('Open Redirect')

Stop the waste.
Protect your environment with Kodem.