cbcvebase.
CVE-2026-45796
published 2026-07-07

CVE-2026-45796: Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3…

PriorityP344medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.43%
36.8th percentile
Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, if the Azure identity-auth mechanism is not being used then restrict access to the corresponding endpoint (`/api/v2/workspaceagents/azure-instance-identity`) using ingress firewall and/or proxy ACLs.

Affected

18 ranges
VendorProductVersion rangeFixed in
codercoder< 2.24.52.24.5
codercoder——
codercoder——
codercoder——
codercoder——
codercoder——
codercoder>= 2.29.0 < 2.29.132.29.13
codercoder>= 2.30.0 < 2.30.82.30.8
codercoder>= 2.31.0 < 2.31.122.31.12
codercoder>= 2.32.0 < 2.32.22.32.2
codercoder>= 2.33.0 < 2.33.32.33.3
github.comcoder_coder0 – 0.27.3—
github.comcoder_coder_v2>= 0 < 2.24.52.24.5
github.comcoder_coder_v2>= 2.29.0 < 2.29.132.29.13
github.comcoder_coder_v2>= 2.30.0 < 2.30.82.30.8
github.comcoder_coder_v2>= 2.31.0 < 2.31.122.31.12
github.comcoder_coder_v2>= 2.32.0-rc.0 < 2.32.22.32.2
github.comcoder_coder_v2>= 2.33.0-rc.0 < 2.33.32.33.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.