v2.28.10
Stable (since February 03, 2026)
Changelog
Security Patch
-
Bump alpine to 3.23.3 in release/2.29 (#21879, 72afd3677)
Updated the base image and dependencies to include patched version of OpenSSL. This addresses a critical stack-based buffer overflow in CMS message parsing that could lead to remote code execution or denial of service (CVE-2025-15467). There's no indication that this issue was exploitable in default Coder installations.
Compare: v2.28.9...v2.28.10
Container image
docker pull ghcr.io/coder/coder:v2.28.10
Install/upgrade
Refer to our docs to install or upgrade Coder, or use a release asset below.