CVE-2026-55430
published 2026-07-08CVE-2026-55430: Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app…
PriorityP334medium6.8CVSS 3.1
AVNACLPRLUIRSCCHINAN
EPSS
0.21%
11.3th percentile
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `fetch()` calls. Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip `X-Forwarded-Host`. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 trusts `X-Forwarded-Host` only from configured trusted proxies and otherwise resolves the routing host from the verified request host. As a workaround, place an upstream reverse proxy that strips or overwrites `X-Forwarded-Host` on untrusted requests.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| coder | coder | < 2.29.17 | 2.29.17 |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | — | — |
| coder | coder | >= 2.30.0 < 2.32.7 | 2.32.7 |
| coder | coder | >= 2.33.0 < 2.33.8 | 2.33.8 |
| coder | coder | >= 2.34.0 < 2.34.2 | 2.34.2 |
| github.com | coder_coder_v2 | >= 0 < 2.29.17 | 2.29.17 |
| github.com | coder_coder_v2 | >= 2.30.0 < 2.32.7 | 2.32.7 |
| github.com | coder_coder_v2 | >= 2.33.0 < 2.33.8 | 2.33.8 |
| github.com | coder_coder_v2 | >= 2.34.0 < 2.34.2 | 2.34.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Workspace App Proxy RequestHost client-side enforcement of server-side security
vuldb·2026-07-08·CVSS 5.8
CVE-2026-55430 [MEDIUM] Coder up to 2.29.16/2.32.6/2.33.7/2.34.1 Workspace App Proxy RequestHost client-side enforcement of server-side security
A vulnerability marked as critical has been reported in Coder up to 2.29.16/2.32.6/2.33.7/2.34.1. Affected by this issue is the function RequestHost of the component Workspace App Proxy. The manipulation leads to client-side enforcement of server-side security.
This vulnerability is documented as CVE-2026-55430. The attack can be initiated remotely. There is not any exploit available.
GHSA
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
ghsa·2026-07-06
CVE-2026-55430 [MEDIUM] CWE-345 Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access
### Summary
The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `fetch()` calls.
> **Note:** Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip `X-Forwarded-Host`.
### Impact
App session cookies are scoped to the wildcard parent domain so the browser attaches them to any app subdomain. An attacker who controls
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/coder/coder/pull/26204https://github.com/coder/coder/releases/tag/v2.29.17https://github.com/coder/coder/releases/tag/v2.32.7https://github.com/coder/coder/releases/tag/v2.33.8https://github.com/coder/coder/releases/tag/v2.34.2https://github.com/coder/coder/security/advisories/GHSA-5g4w-3vw9-478w
2026-07-08
Published