CVE-2026-55428General(coder / coder)

LOWCVSS 8.2 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates each `AllowedIPs` prefix against the authenticating agent's UUID just like `Addresses`. As a workaround, monitor coordinator logs for agents advertising unexpected `AllowedIPs` prefixes.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coder

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
coder

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-08: 207-08
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-55428 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator v… https://www.cve.org/CVERecord?id=CVE-2026-55428 ----- Traducción: CVE-2026-55428 Cod… http://infoflow.cloud`

    Post summary

    The statement references a CVE and its affected versions but lacks evidence of PoC, exploit, active use, or remediation, resulting in a general informational label.

    0000038
    91 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-55428 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator v… https://www.cve.org/CVERecord?id=CVE-2026-55428

    Post summary

    The post references CVE‑2026‑55428, noting that Coder versions prior to 2.29.7, 2.32.7, 2.33.8, and 2.34.2 have a vulnerability related to provisioning remote development environments via Terraform, and it links to the CVE record for further details.

    00000643
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercoder-go-

Explore more