CVE-2026-45796

Coder allows organizations to provision remote development environments via Terraform. Versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 are vulnerable to unauthenticated semi-blind Server-Side Request Forgery (SSRF) via the Azure instance identity endpoint (`POST /api/v2/workspaceagents/azure-instance-identity`). An external attacker can force the Coder server to issue HTTP GET requests to arbitrary internal or external hosts by submitting a crafted PKCS#7 signature. The server does not return the target's response body, but error messages in the API response reveal whether the target is reachable and what type of failure occurred. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, if the Azure identity-auth mechanism is not being used then restrict access to the corresponding endpoint (`/api/v2/workspaceagents/azure-instance-identity`) using ingress firewall and/or proxy ACLs.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*

History

08 Jul 2026, 19:47

Type Values Removed Values Added
CPE cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:*
First Time Coder coder
Coder
References () https://github.com/coder/coder/commit/57b11d405f17492aa789d4b9ff33366f961a37f8 - () https://github.com/coder/coder/commit/57b11d405f17492aa789d4b9ff33366f961a37f8 - Patch
References () https://github.com/coder/coder/pull/25274 - () https://github.com/coder/coder/pull/25274 - Issue Tracking, Patch
References () https://github.com/coder/coder/releases/tag/v2.24.5 - () https://github.com/coder/coder/releases/tag/v2.24.5 - Release Notes
References () https://github.com/coder/coder/releases/tag/v2.29.13 - () https://github.com/coder/coder/releases/tag/v2.29.13 - Release Notes
References () https://github.com/coder/coder/releases/tag/v2.30.8 - () https://github.com/coder/coder/releases/tag/v2.30.8 - Release Notes
References () https://github.com/coder/coder/releases/tag/v2.31.12 - () https://github.com/coder/coder/releases/tag/v2.31.12 - Release Notes
References () https://github.com/coder/coder/releases/tag/v2.32.2 - () https://github.com/coder/coder/releases/tag/v2.32.2 - Release Notes
References () https://github.com/coder/coder/releases/tag/v2.33.3 - () https://github.com/coder/coder/releases/tag/v2.33.3 - Release Notes
References () https://github.com/coder/coder/security/advisories/GHSA-686c-7vgv-v3fx - () https://github.com/coder/coder/security/advisories/GHSA-686c-7vgv-v3fx - Patch, Vendor Advisory

07 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-07 22:16

Updated : 2026-07-08 19:47


NVD link : CVE-2026-45796

Mitre link : CVE-2026-45796

CVE.ORG link : CVE-2026-45796


JSON object : View

Products Affected

coder

  • coder
CWE
CWE-918

Server-Side Request Forgery (SSRF)