CVE-2026-55434: Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints
(updated )
AI Bridge provider handlers read request bodies with io.ReadAll without a maximum size so an authenticated user with AI Bridge access could send an arbitrarily large body and exhaust memory.
Note: Exploitation requires authenticated access to the AI Bridge endpoints and the impact is limited to availability (denial of service).
References
Code Behaviors & Features
Detect and mitigate CVE-2026-55434 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →