CRITICAL9.1CVE-2026-46354Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder >= 2.33.0-rc.0, < 2.33.3
CRITICAL9.1CVE-2026-46354Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder from 0, < 2.24.5, >= 2.29.0, < 2.29.13, >= 2.30.0, < 2.30.8, >= 2.31.0, < 2.31.12, >= 2.32.0-rc.0, < 2.32.2, >= 2.33.0-rc.0, < 2.33.3
HIGH8.7Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH8.7Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
HIGH8.3Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH8.3Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
HIGH8.2Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH8.2Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
HIGH8.2Incorrect email domain verification in github.com/coder/coder
>= 2.8.0, < 2.8.4
HIGH8.2Incorrect email domain verification in github.com/coder/coder
from 0, < 2.6.1, >= 2.7.0, < 2.7.3, >= 2.8.0, < 2.8.4
HIGH8.1Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
from 0, < 2.29.7
HIGH8.1Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
from 0, < 2.29.7, >= 2.30.0, < 2.30.2
HIGH8.1Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
>= 2.22.0, < 2.24.4
HIGH8.1Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
>= 2.22.0, < 2.24.4, >= 2.25.0, < 2.25.2
HIGH7.8Coder logs sensitive objects unsanitized in github.com/coder/coder
from 0, < 2.26.5
HIGH7.8Coder logs sensitive objects unsanitized in github.com/coder/coder
from 0, < 2.26.5, >= 2.27.0, < 2.27.7, >= 2.28.0, < 2.28.4
HIGH7.7Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH7.7Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
HIGH7.4Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH7.4Coder's AI Bridge Proxy skips TLS certificate verification in default configuration in github.com/coder/coder
>= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
HIGH7.4Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH7.4Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
HIGH7.4Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH7.4Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
HIGH7.2Coder: User-admin role can reset owner account password in github.com/coder/coder
>= 2.34.0, < 2.34.2
HIGH7.2Coder: User-admin role can reset owner account password in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM6.5Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM6.5Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints in github.com/coder/coder
>= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM6.5Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM6.5Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
>= 2.17.0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM6.5Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
>= 2.33.0-rc.0, < 2.33.3
MEDIUM6.5Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
from 0, < 2.24.5, >= 2.29.0, < 2.29.13, >= 2.30.0, < 2.30.8, >= 2.31.0, < 2.31.12, >= 2.32.0-rc.0, < 2.32.2, >= 2.33.0-rc.0, < 2.33.3
MEDIUM5.8Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM5.8Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM5.8Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM5.8Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM5.4Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM5.4Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM5.4Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM5.4Suspended Coder users retain access to AI Bridge LLM proxy endpoints in github.com/coder/coder
>= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM5.4Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM5.4Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM5.4Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM5.4Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
from 0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2
MEDIUM4.9Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
>= 2.34.0, < 2.34.2
MEDIUM4.9Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service in github.com/coder/coder
>= 2.24.0, < 2.29.17, >= 2.30.0, < 2.32.7, >= 2.33.0, < 2.33.8, >= 2.34.0, < 2.34.2