CVE-2026-45796

MEDIUM

Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint

Title source: cna
STIX 2.1

Description

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, if the Azure identity-auth mechanism is not being used then restrict access to the corresponding endpoint (`/api/v2/workspaceagents/azure-instance-identity`) using ingress firewall and/or proxy ACLs.

References (9)

Core 9
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/pull/25274
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.24.5
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.29.13
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.30.8
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.31.12
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.32.2
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.33.3

Scores

CVSS v3 6.5
EPSS 0.0034
EPSS Percentile 26.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (6)
coder/coder < 2.24.5 (2 CPE variants)
coder/coder >= 2.29.0, < 2.29.13
coder/coder >= 2.30.0, < 2.30.8
coder/coder >= 2.31.0, < 2.31.12
coder/coder >= 2.32.0-rc.0, < 2.32.2
coder/coder >= 2.33.0-rc.0, < 2.33.3
Published Jul 07, 2026
Tracked Since Jul 08, 2026