CVE-2026-45796
published 2026-07-07CVE-2026-45796: Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3…
PriorityP344medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.43%
36.8th percentile
Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, if the Azure identity-auth mechanism is not being used then restrict access to the corresponding endpoint (`/api/v2/workspaceagents/azure-instance-identity`) using ingress firewall and/or proxy ACLs.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | < 2.24.5 | 2.24.5 |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.29.0 < 2.29.13 | 2.29.13 |
| coder | coder | >= 2.30.0 < 2.30.8 | 2.30.8 |
| coder | coder | >= 2.31.0 < 2.31.12 | 2.31.12 |
| coder | coder | >= 2.32.0 < 2.32.2 | 2.32.2 |
| coder | coder | >= 2.33.0 < 2.33.3 | 2.33.3 |
| github.com | coder_coder | 0 – 0.27.3 | — |
| github.com | coder_coder_v2 | >= 0 < 2.24.5 | 2.24.5 |
| github.com | coder_coder_v2 | >= 2.29.0 < 2.29.13 | 2.29.13 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.30.8 | 2.30.8 |
| github.com | coder_coder_v2 | >= 2.31.0 < 2.31.12 | 2.31.12 |
| github.com | coder_coder_v2 | >= 2.32.0-rc.0 < 2.32.2 | 2.32.2 |
| github.com | coder_coder_v2 | >= 2.33.0-rc.0 < 2.33.3 | 2.33.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.33.2 Azure Instance Identity Endpoint azure-instance-identity server-side request forgery
vuldb·2026-07-08·CVSS 6.5
CVE-2026-45796 [MEDIUM] Coder up to 2.33.2 Azure Instance Identity Endpoint azure-instance-identity server-side request forgery
A vulnerability marked as problematic has been reported in Coder up to 2.33.2. This vulnerability affects unknown code of the file /api/v2/workspaceagents/azure-instance-identity of the component Azure Instance Identity Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-45796. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
ghsa·2026-05-19
CVE-2026-45796 [MEDIUM] CWE-918 Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
## Summary
Unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred.
## Details
The `POST /api/v2/workspaceagents/azure-instance-identity` endpoint accepts a PKCS#7 signature without authentication. During certificate chain verification, [`azureidentity.Validate()`](https://github.com/coder/coder/blob/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/commit/57b11d405f17492aa789d4b9ff33366f961a37f8https://github.com/coder/coder/pull/25274https://github.com/coder/coder/releases/tag/v2.24.5https://github.com/coder/coder/releases/tag/v2.29.13https://github.com/coder/coder/releases/tag/v2.30.8https://github.com/coder/coder/releases/tag/v2.31.12https://github.com/coder/coder/releases/tag/v2.32.2https://github.com/coder/coder/releases/tag/v2.33.3https://github.com/coder/coder/security/advisories/GHSA-686c-7vgv-v3fx
2026-07-07
Published