CVE-2026-55428
published 2026-07-08CVE-2026-55428: Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet…
PriorityP349high8.2CVSS 3.1
AVNACHPRLUINSCCHIHAN
EPSS
0.40%
34.5th percentile
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates each `AllowedIPs` prefix against the authenticating agent's UUID just like `Addresses`. As a workaround, monitor coordinator logs for agents advertising unexpected `AllowedIPs` prefixes.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | < 2.29.17 | 2.29.17 |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.30.0 < 2.32.7 | 2.32.7 |
| coder | coder | >= 2.33.0 < 2.33.8 | 2.33.8 |
| coder | coder | >= 2.34.0 < 2.34.2 | 2.34.2 |
| github.com | coder_coder_v2 | >= 0 < 2.29.17 | 2.29.17 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.32.7 | 2.32.7 |
| github.com | coder_coder_v2 | >= 2.33.0 < 2.33.8 | 2.33.8 |
| github.com | coder_coder_v2 | >= 2.34.0 < 2.34.2 | 2.34.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Tailnet Coordinator AllowedIPs input validation
vuldb·2026-07-08·CVSS 8.2
CVE-2026-55428 [HIGH] Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Tailnet Coordinator AllowedIPs input validation
A vulnerability classified as critical has been found in Coder up to 2.29.16/2.32.6/2.33.7/2.34.1. Affected by this vulnerability is an unknown functionality of the component Tailnet Coordinator. The manipulation of the argument AllowedIPs leads to improper input validation.
This vulnerability is traded as CVE-2026-55428. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
ghsa·2026-07-06
CVE-2026-55428 [HIGH] CWE-285 Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
### Summary
The tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration.
### Impact
A malicious workspace agent can advertise arbitrary `AllowedIPs` prefixes including another agent's tailnet address. Coder's `ServerTailnet` routes to agents by tailnet IP so an agent that claims a victim's prefix can intercept web terminal and workspace app traffic and serve spoofed content. Exploitation requires an authenticated user with a running workspace and a modified agent binar
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/pull/26144https://github.com/coder/coder/releases/tag/v2.29.17https://github.com/coder/coder/releases/tag/v2.32.7https://github.com/coder/coder/releases/tag/v2.33.8https://github.com/coder/coder/releases/tag/v2.34.2https://github.com/coder/coder/security/advisories/GHSA-wrq8-fcv5-8hvp
2026-07-08
Published