coder kayıtları
coder üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-287 Improper Authentication2
- CWE-285 Improper Authorization2
- CWE-862 Missing Authorization2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-277 Insecure Inherited Permissions1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
37İzleyin | CVE-2023-26114İstismar yok | Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.coder · code-server · CWE-1385 | Kritik9,3 | — | %0,3 | 23 Mar 2023 |
36İzleyin | CVE-2026-44454İstismar yok | Coder vulnerable to workspace auto-creation via crafted URL parameters without user consentcoder · coder · CWE-78 | Yüksek8,8 | — | %2,6 | 7 Tem 2026 |
36İzleyin | CVE-2026-46354İstismar yok | Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theftcoder · coder · CWE-347 | Kritik9,1 | — | %0,3 | 7 Tem 2026 |
34İzleyin | CVE-2026-55429İstismar yok | Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app IDcoder · coder · CWE-639 | Yüksek8,7 | — | %0,5 | 7 Tem 2026 |
34İzleyin | CVE-2026-35454İstismar yok | Code Extension Marketplace has a Zip Slip Path Traversalcoder · code-marketplace · CWE-22 | Yüksek8,7 | — | %0,4 | 6 Nis 2026 |
33İzleyin | CVE-2026-55427İstismar yok | Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`coder · coder · CWE-74 | Yüksek8,3 | — | %0,5 | 7 Tem 2026 |
32İzleyin | CVE-2024-27918İstismar yok | Coder's OIDC authentication allows email with partially matching domain to registercoder · coder · CWE-20 | Yüksek8,2 | — | %1,0 | 20 Mar 2024 |
32İzleyin | CVE-2026-55428İstismar yok | Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinatorcoder · coder · CWE-285 | Yüksek8,2 | — | %0,4 | 7 Tem 2026 |
32İzleyin | CVE-2025-58437İstismar yok | Coder's privilege escalation vulnerability could lead to a cross workspace compromisecoder · coder · CWE-277 | Yüksek8,1 | — | %0,4 | 5 Eyl 2025 |
30İzleyin | CVE-2021-3810İstismar yok | Inefficient Regular Expression Complexity in cdr/code-servercoder · code-server · CWE-1333 | Yüksek7,5 | — | %1,3 | 17 Eyl 2021 |
29İzleyin | CVE-2026-55076İstismar yok | Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linkingcoder · coder · CWE-287 | Yüksek7,4 | — | %0,6 | 7 Tem 2026 |
29İzleyin | CVE-2026-55075İstismar yok | Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypasscoder · coder · CWE-287 | Yüksek7,4 | — | %0,5 | 7 Tem 2026 |
29İzleyin | CVE-2026-55436İstismar yok | Coder's AI Bridge Proxy skips TLS certificate verification in default configurationcoder · coder · CWE-295 | Yüksek7,4 | — | %0,3 | 7 Tem 2026 |
28İzleyin | CVE-2026-55077İstismar yok | Coder: User-admin role can reset owner account passwordcoder · coder · CWE-285 | Yüksek7,2 | — | %0,6 | 7 Tem 2026 |
27İzleyin | CVE-2026-55438İstismar yok | Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofingcoder · coder · CWE-346 | Orta6,8 | — | %0,2 | 7 Tem 2026 |
27İzleyin | CVE-2026-55430İstismar yok | Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data accesscoder · coder · CWE-345 | Orta6,8 | — | %0,2 | 7 Tem 2026 |
26İzleyin | CVE-2026-55079İstismar yok | Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of servicecoder · coder · CWE-789 | Orta6,5 | — | %0,6 | 7 Tem 2026 |
26İzleyin | CVE-2026-55078İstismar yok | Coder: Zip upload decompression lacks aggregate size limit, enabling denial of servicecoder · coder · CWE-409 | Orta6,5 | — | %0,6 | 7 Tem 2026 |
26İzleyin | CVE-2026-55434İstismar yok | Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpointscoder · coder · CWE-770 | Orta6,5 | — | %0,6 | 7 Tem 2026 |
26İzleyin | CVE-2026-45796İstismar yok | Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpointcoder · coder · CWE-918 | Orta6,5 | — | %0,4 | 7 Tem 2026 |
26İzleyin | CVE-2025-59956İstismar yok | AgentAPI exposed user chat history via a DNS rebinding attackcoder · agentapi · CWE-350 | Orta6,5 | — | %0,4 | 30 Eyl 2025 |
24İzleyin | CVE-2021-42648İstismar yok | Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted Ucoder · code-server · CWE-79 | Orta6,1 | — | %0,8 | 11 May 2022 |
24İzleyin | CVE-2026-55431İstismar yok | Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace appscoder · coder · CWE-522 | Orta6,1 | — | %0,3 | 7 Tem 2026 |
22İzleyin | CVE-2025-66411İstismar yok | Coder logged sensitive objects unsanitizedcoder · coder · CWE-532 | Orta5,5 | — | %0,2 | 3 Ara 2025 |
21İzleyin | CVE-2026-55433İstismar yok | Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containerscoder · coder · CWE-862 | Orta5,4 | — | %0,4 | 7 Tem 2026 |
- CVE-2023-2611437İzleyin
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes.
KritikCVSS 9,3İstismar yokEPSS %0coder · code-server23 Mar 2023
- CVE-2026-4445436İzleyin
Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent
YüksekCVSS 8,8İstismar yokEPSS %3coder · coder7 Tem 2026
- CVE-2026-4635436İzleyin
Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft
KritikCVSS 9,1İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2026-5542934İzleyin
Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID
YüksekCVSS 8,7İstismar yokEPSS %1coder · coder7 Tem 2026
- CVE-2026-3545434İzleyin
Code Extension Marketplace has a Zip Slip Path Traversal
YüksekCVSS 8,7İstismar yokEPSS %0coder · code-marketplace6 Nis 2026
- CVE-2026-5542733İzleyin
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
YüksekCVSS 8,3İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2024-2791832İzleyin
Coder's OIDC authentication allows email with partially matching domain to register
YüksekCVSS 8,2İstismar yokEPSS %1coder · coder20 Mar 2024
- CVE-2026-5542832İzleyin
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
YüksekCVSS 8,2İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2025-5843732İzleyin
Coder's privilege escalation vulnerability could lead to a cross workspace compromise
YüksekCVSS 8,1İstismar yokEPSS %0coder · coder5 Eyl 2025
- CVE-2021-381030İzleyin
Inefficient Regular Expression Complexity in cdr/code-server
YüksekCVSS 7,5İstismar yokEPSS %1coder · code-server17 Eyl 2021
- CVE-2026-5507629İzleyin
Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking
YüksekCVSS 7,4İstismar yokEPSS %1coder · coder7 Tem 2026
- CVE-2026-5507529İzleyin
Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass
YüksekCVSS 7,4İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2026-5543629İzleyin
Coder's AI Bridge Proxy skips TLS certificate verification in default configuration
YüksekCVSS 7,4İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2026-5507728İzleyin
Coder: User-admin role can reset owner account password
YüksekCVSS 7,2İstismar yokEPSS %1coder · coder7 Tem 2026
- CVE-2026-5543827İzleyin
Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing
OrtaCVSS 6,8İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2026-5543027İzleyin
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
OrtaCVSS 6,8İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2026-5507926İzleyin
Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service
OrtaCVSS 6,5İstismar yokEPSS %1coder · coder7 Tem 2026
- CVE-2026-5507826İzleyin
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
OrtaCVSS 6,5İstismar yokEPSS %1coder · coder7 Tem 2026
- CVE-2026-5543426İzleyin
Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
OrtaCVSS 6,5İstismar yokEPSS %1coder · coder7 Tem 2026
- CVE-2026-4579626İzleyin
Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint
OrtaCVSS 6,5İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2025-5995626İzleyin
AgentAPI exposed user chat history via a DNS rebinding attack
OrtaCVSS 6,5İstismar yokEPSS %0coder · agentapi30 Eyl 2025
- CVE-2021-4264824İzleyin
Cross-site scripting (XSS) vulnerability exists in Coder Code-Server before 3.12.0, allows attackers to execute arbitrary code via crafted U
OrtaCVSS 6,1İstismar yokEPSS %1coder · code-server11 May 2022
- CVE-2026-5543124İzleyin
Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps
OrtaCVSS 6,1İstismar yokEPSS %0coder · coder7 Tem 2026
- CVE-2025-6641122İzleyin
Coder logged sensitive objects unsanitized
OrtaCVSS 5,5İstismar yokEPSS %0coder · coder3 Ara 2025
- CVE-2026-5543321İzleyin
Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers
OrtaCVSS 5,4İstismar yokEPSS %0coder · coder7 Tem 2026