Threats Tagged 'ghsa-f962-qm93-mj4c'
View all threats tagged with 'ghsa-f962-qm93-mj4c'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-f962-qm93-mj4c'
Click on any threat for detailed analysis and mitigation recommendations
0 ### Summary `NewDataBuilder` in `provisionersdk/proto/dataupload.go` allocated a byte slice using the client-supplied `FileSize` from a `DataUpload` message without an upper-bound check. Although the DRPC wire limit is 4 MiB, the `FileSize` value itself was unconstrained ### Impact An authenticated user able to reach the provisioner daemon serve endpoint could send a roughly 50-byte message declaring a huge `FileSize` (for example 1 TiB), triggering an unrecoverable Go out-of-memory abort that terminates `coderd`. This is a single-message denial of service affecting the entire deployment. ### Patches The fix validates `FileSize` against an upper bound (`MaxFileSize = 100 MiB`) before allocation. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds Restrict access to the provisioner daemon serve endpoint to trusted provisioner daemon service accounts. ### Resources - Fix: #25710 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22442) for independently disclosing this issue! Join the discussion | GCVE Database | 07/06/2026, 20:54:41 UTC Added: 07/06/2026, 23:02:27 UTC |
Showing 1 to 1 of 1 result