High severityNVD Advisory· Published Jul 7, 2026· Updated Jul 8, 2026
Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
CVE-2026-55428
Description
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's Addresses derive from its authenticated UUID but applies no equivalent check to AllowedIPs. The coordinator forwards agent-supplied AllowedIPs verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates each AllowedIPs prefix against the authenticating agent's UUID just like Addresses. As a workaround, monitor coordinator logs for agents advertising unexpected AllowedIPs prefixes.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/coder/coder/v2Go | >= 2.34.0, < 2.34.2 | 2.34.2 |
github.com/coder/coder/v2Go | >= 2.33.0, < 2.33.8 | 2.33.8 |
github.com/coder/coder/v2Go | >= 2.30.0, < 2.32.7 | 2.32.7 |
github.com/coder/coder/v2Go | < 2.29.17 | 2.29.17 |
Affected products
1Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-wrq8-fcv5-8hvpghsaADVISORY
- github.com/coder/coder/pull/26144ghsax_refsource_MISCWEB
- github.com/coder/coder/releases/tag/v2.29.17mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.32.7mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.33.8mitrex_refsource_MISC
- github.com/coder/coder/releases/tag/v2.34.2mitrex_refsource_MISC
- github.com/coder/coder/security/advisories/GHSA-wrq8-fcv5-8hvpghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.