Affected by GO-2025-3921
and 20 other vulnerabilities
GO-2025-3921 : Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token in github.com/coder/coder
GO-2025-3938 : Coder vulnerable to privilege escalation could lead to a cross workspace compromise in github.com/coder/coder
GO-2025-4182 : Coder logs sensitive objects unsanitized in github.com/coder/coder
GO-2026-5169 : Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint in github.com/coder/coder
GO-2026-5196 : Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft in github.com/coder/coder
GO-2026-5897 : Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent in github.com/coder/coder
GO-2026-5906 : Coder: User-admin role can reset owner account password in github.com/coder/coder
GO-2026-5907 : Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking in github.com/coder/coder
GO-2026-5908 : Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass in github.com/coder/coder
GO-2026-5909 : Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID in github.com/coder/coder
GO-2026-5913 : Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh` in github.com/coder/coder
GO-2026-5915 : Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator in github.com/coder/coder
GO-2026-5916 : Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service in github.com/coder/coder
GO-2026-5917 : Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access in github.com/coder/coder
GO-2026-5918 : Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing in github.com/coder/coder
GO-2026-5919 : Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component in github.com/coder/coder
GO-2026-5922 : Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers in github.com/coder/coder
GO-2026-5924 : Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps in github.com/coder/coder
GO-2026-5926 : Coder's sub-agent app registration bypasses template port-sharing policy enforcement in github.com/coder/coder
GO-2026-6265 : Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison in github.com/coder/coder
GO-2026-6267 : Coder: Stored HTML injection via unescaped ApplicationName and LogoURL appearance settings in github.com/coder/coder
Discover Packages
github.com/coder/coder/v2
codersdk
wsjson
package
Version:
v2.22.1
Opens a new window with list of versions in this module.
Published: May 20, 2025
License: AGPL-3.0
Opens a new window with license information.
Imports: 6
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
Documentation
¶
type Decoder[T any ] struct {
}
NewDecoder creates a JSON-over-websocket decoder for type T, which must be deserializable from
JSON.
func (d *Decoder [T]) Chan() <-chan T
Chan returns a `chan` that you can read incoming messages from. The returned
`chan` will be closed when the WebSocket connection is closed. If there is an
error reading from the WebSocket or decoding a value the WebSocket will be
closed.
Safety: Chan must only be called once. Successive calls will panic.
nolint: revive // complains that Encoder has the same function name
type Encoder[T any ] struct {
}
NewEncoder creates a JSON-over websocket encoder for the type T, which must be JSON-serializable.
You may then call Encode() to send objects over the websocket. Creating an Encoder closes the
websocket for reading, turning it into a unidirectional write stream of JSON-encoded objects.
nolint: revive // complains that Decoder has the same function name
type Stream[R any , W any ] struct {
}
Stream is a two-way messaging interface over a WebSocket connection.
func (s *Stream [R, W]) Chan() <-chan R
Chan returns a `chan` that you can read incoming messages from. The returned
`chan` will be closed when the WebSocket connection is closed. If there is an
error reading from the WebSocket or decoding a value the WebSocket will be
closed.
Safety: Chan must only be called once. Successive calls will panic.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.