CVE-2026-55430Disclosure(coder / coder)

LOWCVSS 6.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `fetch()` calls. Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip `X-Forwarded-Host`. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 trusts `X-Forwarded-Host` only from configured trusted proxies and otherwise resolves the routing host from the verified request host. As a workaround, place an upstream reverse proxy that strips or overwrites `X-Forwarded-Host` on untrusted requests.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-441

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coder

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
coder

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-08: 2Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55430 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy r… https://www.cve.org/CVERecord?id=CVE-2026-55430 ----- Traducción: CVE-2026-55430 Cod… http://infoflow.cloud`

    Post summary

    The brief note identifies CVE-2026-55430 affecting older Coder versions prior to 2.29.7, 2.32.7, 2.33.8, and 2.34.2, with links to the CVE record for more details.

    0000042
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55430 Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy r… https://www.cve.org/CVERecord?id=CVE-2026-55430

    Post summary

    The text announces CVE‑2026‑55430 as a vulnerability in Coder’s Terraform‑based remote development environments, indicating affected versions but providing no evidence of exploitation, PoCs, or patches.

    00000632
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcodercoder-go-

Explore more