CVE-2026-55430

MEDIUM

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

Title source: cna
STIX 2.1

Description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `fetch()` calls. Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip `X-Forwarded-Host`. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 trusts `X-Forwarded-Host` only from configured trusted proxies and otherwise resolves the routing host from the verified request host. As a workaround, place an upstream reverse proxy that strips or overwrites `X-Forwarded-Host` on untrusted requests.

References (6)

Core 6
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/pull/26204
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.29.17
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.32.7
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.33.8
X_Refsource_Misc x_refsource_misc
https://github.com/coder/coder/releases/tag/v2.34.2

Scores

CVSS v3 5.8
EPSS 0.0014
EPSS Percentile 3.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-345 CWE-441
Status published
Products (4)
coder/coder < 2.29.17 (2 CPE variants)
coder/coder >= 2.30.0, < 2.32.7
coder/coder >= 2.33.0, < 2.33.8
coder/coder >= 2.34.0, < 2.34.2
Published Jul 08, 2026
Tracked Since Jul 08, 2026