CVE-2026-55435
Description
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via Server.IsAuthorized in coderd/aibridgedserver, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via DELETE /api/v2/users/{user}/keys.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/coder/coder/v2Go | >= 2.34.0, < 2.34.2 | 2.34.2 |
github.com/coder/coder/v2Go | >= 2.33.0, < 2.33.8 | 2.33.8 |
github.com/coder/coder/v2Go | >= 2.30.0, < 2.32.7 | 2.32.7 |
Affected products
3- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
9- github.com/coder/coder/commit/0d2c9f904a8b75b888140fcc8fbf4633660cc787nvdPatchWEB
- github.com/coder/coder/pull/26164nvdIssue TrackingPatchWEB
- github.com/coder/coder/pull/26173nvdIssue TrackingPatchWEB
- github.com/coder/coder/security/advisories/GHSA-wqxv-w64v-5wh6nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-wqxv-w64v-5wh6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-55435ghsaADVISORY
- github.com/coder/coder/releases/tag/v2.32.7nvdRelease NotesWEB
- github.com/coder/coder/releases/tag/v2.33.8nvdRelease NotesWEB
- github.com/coder/coder/releases/tag/v2.34.2nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.