Coder maintains a focused portfolio of development and remote-code-execution tools, including its flagship Code Server product and cloud development platform, that serve as critical infrastructure for collaborative development environments. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in access-control and input-handling weakness classes—including authentication bypass by spoofing, path traversal, cross-site scripting, and improper input validation—that reflect the exposure of code and workspace boundaries to untrusted network input. Defenders should prioritize patching in this vendor's tooling, particularly where instances are exposed to team networks or the internet; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coder over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-55429HIGH Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an exis | Jul 8, 2026 | 8.7 | 38 | NO | NO |
CVE-2026-46354CRITICAL Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Val | Jul 7, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-44454HIGH Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30.2, the `dotfiles` registry module passed unsanitized user i | Jul 7, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-55427HIGH Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplie | Jul 8, 2026 | 8.3 | 37 | NO | NO |
CVE-2026-55428HIGH Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that | Jul 8, 2026 | 8.2 | 36 | NO | NO |
CVE-2026-55075HIGH Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, two flaws in Coder's OIDC login chained | Jul 7, 2026 | 7.4 | 34 | NO | NO |
CVE-2026-55077HIGH Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `PUT /api/v2/users/{user}/password` | Jul 7, 2026 | 7.2 | 33 | NO | NO |
CVE-2026-55076HIGH Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, Coder's OIDC callback checked `email_ve | Jul 7, 2026 | 7.4 | 33 | NO | NO |
CVE-2026-55436HIGH Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Pr | Jul 8, 2026 | 7.4 | 31 | NO | NO |
CVE-2026-55430MEDIUM Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the ta | Jul 8, 2026 | 6.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coder.
Media articles that mention a CVE ID that affects a product developed by Coder — matched by CVE ID, not by vendor name.