top of page
perceptive_background_267k.jpg

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34…

Published:

7 juli 2026 om 22:00:00

Alert date:

8 juli 2026 om 16:06:44

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Web Technologies, Network Infrastructure

CVE-2026-55436 affects Coder, a platform for provisioning remote development environments via Terraform. Versions 2.30.0 through before 2.32.7, 2.33.8, and 2.34.2 contain a critical TLS misconfiguration in the AI Bridge Proxy (aibridgeproxyd). The proxy's goproxy server defaulted to InsecureSkipVerify: true, meaning outbound HTTPS connections to the Coder access URL would accept any TLS certificate when no upstream proxy was configured. This makes the component vulnerable to man-in-the-middle (MITM) attacks where an attacker with an on-path network position could intercept or tamper with communications. Deployments where the proxy and Coder server are co-located on loopback are effectively unaffected. Fixed versions enforce TLS 1.2 or higher with system root CAs unconditionally. Workarounds include using trusted certificates and securing the network path via loopback or mTLS.

Technical details

Mitigation steps:

Affected products:

Coder 2.30.0
Coder 2.32.x (prior to 2.32.7)
Coder 2.33.x (prior to 2.33.8)
Coder 2.34.x (prior to 2.34.2)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page