


Perceptive Security
SOC/SIEM Consultancy

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34…
Published:
7 juli 2026 om 22:00:00
Alert date:
8 juli 2026 om 16:06:44
Source:
nvd.nist.gov
Cloud & Virtualization, Web Technologies, Network Infrastructure
CVE-2026-55436 affects Coder, a platform for provisioning remote development environments via Terraform. Versions 2.30.0 through before 2.32.7, 2.33.8, and 2.34.2 contain a critical TLS misconfiguration in the AI Bridge Proxy (aibridgeproxyd). The proxy's goproxy server defaulted to InsecureSkipVerify: true, meaning outbound HTTPS connections to the Coder access URL would accept any TLS certificate when no upstream proxy was configured. This makes the component vulnerable to man-in-the-middle (MITM) attacks where an attacker with an on-path network position could intercept or tamper with communications. Deployments where the proxy and Coder server are co-located on loopback are effectively unaffected. Fixed versions enforce TLS 1.2 or higher with system root CAs unconditionally. Workarounds include using trusted certificates and securing the network path via loopback or mTLS.
Technical details
Mitigation steps:
Affected products:
Coder 2.30.0
Coder 2.32.x (prior to 2.32.7)
Coder 2.33.x (prior to 2.33.8)
Coder 2.34.x (prior to 2.34.2)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-55436
https://github.com/coder/coder/pull/26131
https://github.com/coder/coder/releases/tag/v2.32.7
https://github.com/coder/coder/releases/tag/v2.33.8
https://github.com/coder/coder/releases/tag/v2.34.2
https://github.com/coder/coder/security/advisories/GHSA-84rm-42xw-mx52
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
