GHSA-8fxq-53rx-ph5f is a low-severity (CVSS 3.7) vulnerability in github.com/coder/coder/v2. A fix is available for github.com/coder/coder/v2 — see the affected versions and patch details below.
Coder: Login endpoint user enumeration via timing-defense placeholder in password comparison
Real-World Exposure
github.com/coder/coder/v2🐹github.com/coder/coder/v2🐹github.com/coder/coder/v2🐹github.com/coder/coder/v2Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Go packages — download data is not available via public APIs for these ecosystems.
Description
Summary
userpassword.Compare() substituted a placeholder hash derived from the well-known string "hunter2" when the stored hash was empty. Submitting "hunter2" therefore matched accounts with no password hash (nonexistent users and SSO-only users) and a subsequent login-type check returned an HTTP 403 that disclosed the account's login type, versus 401 for password users.
Note: Practical exploitation is limited because the timing side channel is noisy and only reveals whether an account exists.
Impact
An unauthenticated attacker could enumerate valid accounts and their authentication provider by submitting logins with the password "hunter2", distinguishing nonexistent users, SSO users (provider revealed) and password users from the response. This aids credential-stuffing and targeted phishing. No authentication bypass or data access resulted.
Patches
The fix derives the timing-defense placeholder from a secure random value that no supplied password can match.
The fix was backported to all supported release lines:
Workarounds
None.
References
- Fix: #26205
Credits
We'd like to thank Anthropic's Security Team (ANT-2026-22433) for independently disclosing this issue!
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐹Go | github.com/coder/coder/v2 | ≥ 2.34.0&&< 2.34.2 | 2.34.2go get github.com/coder/coder/v2@v2.34.2 |
| 🐹Go | github.com/coder/coder/v2 | ≥ 2.33.0&&< 2.33.8 | 2.33.8go get github.com/coder/coder/v2@v2.33.8 |
| 🐹Go | github.com/coder/coder/v2 | ≥ 2.30.0&&< 2.32.7 | 2.32.7go get github.com/coder/coder/v2@v2.32.7 |
| 🐹Go | github.com/coder/coder/v2 | all versions | 2.29.17go get github.com/coder/coder/v2@v2.29.17 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for github.com/coder/coder/v2, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update github.com/coder/coder/v2 to 2.34.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-8fxq-53rx-ph5f is resolved across your whole dependency graph.
Workarounds
Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.
Frequently Asked Questions
Is GHSA-8fxq-53rx-ph5f in your dependencies?
Find it across Go, including transitive dependencies.