Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
Description
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.17.0 and prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, POST /api/v2/files converts zip uploads to tar in memory via CreateTarFromZip, which enforced a per-entry size limit but no aggregate limit on total decompressed output, writing to an unbounded in-memory buffer. Exploitation requires authenticated file-upload access and the impact is limited to availability (denial of service). The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 adds a metadata preflight check that sums projected entry sizes and a streaming writer that enforces the aggregate limit during decompression. As a workaround, restrict file-upload permissions to trusted users or place a reverse proxy with request-body size limits in front of coderd.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/coder/coder/v2Go | >= 2.34.0, < 2.34.2 | 2.34.2 |
github.com/coder/coder/v2Go | >= 2.33.0, < 2.33.8 | 2.33.8 |
github.com/coder/coder/v2Go | >= 2.30.0, < 2.32.7 | 2.32.7 |
github.com/coder/coder/v2Go | >= 2.17.0, < 2.29.17 | 2.29.17 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-2mg2-p7r7-g27fghsaADVISORY
- github.com/coder/coder/pull/25877ghsax_refsource_MISCWEB
- github.com/coder/coder/releases/tag/v2.29.17mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.32.7mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.33.8mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.34.2mitrex_refsource_MISC
- github.com/coder/coder/security/advisories/GHSA-2mg2-p7r7-g27fghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.