CVE-2026-55428: Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Published Jul 6, 2026
·
Updated

Summary

The tailnet coordinator validates that an agent's Addresses derive from its authenticated UUID but applies no equivalent check to AllowedIPs. The coordinator forwards agent-supplied AllowedIPs verbatim to tunnel peers which install them into the WireGuard peer configuration.

Impact

A malicious workspace agent can advertise arbitrary AllowedIPs prefixes including another agent's tailnet address. Coder's ServerTailnet routes to agents by tailnet IP so an agent that claims a victim's prefix can intercept web terminal and workspace app traffic and serve spoofed content. Exploitation requires an authenticated user with a running workspace and a modified agent binary.

Patches

The fix validates each AllowedIPs prefix against the authenticating agent's UUID just like Addresses.

The fix was backported to all supported release lines:

| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 | | 2.29 (ESR) | v2.29.17 |

Workarounds

Operators who cannot upgrade immediately should monitor coordinator logs for agents advertising unexpected AllowedIPs prefixes.

Resources

- Fix: #26144

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22451) for independently disclosing this issue!

Other sources

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's Addresses derive from its authenticated UUID but applies no equivalent check to AllowedIPs. The coordinator forwards agent-supplied AllowedIPs verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates each AllowedIPs prefix against the authenticating agent's UUID just like Addresses. As a workaround, monitor coordinator logs for agents advertising unexpected AllowedIPs prefixes.

MITRE

Affected Software

8 affected componentsFixes available
go/github.com/coder/coder/v2<2.29.17
2.29.17
go/github.com/coder/coder/v2>=2.30.0<2.32.7
2.32.7
go/github.com/coder/coder/v2>=2.33.0<2.33.8
2.33.8
go/github.com/coder/coder/v2>=2.34.0<2.34.2
2.34.2
Coder Coder Go<2.29.17
Coder Coder Go>=2.30.0<2.32.7
Coder Coder Go>=2.33.0<2.33.8
Coder Coder Go>=2.34.0<2.34.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.29.17
  2. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.32.7
  3. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.33.8
  4. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.34.2
  5. Upgrade

    Upgrade Coder tailnet coordinator to a version that resolves this vulnerability.

    Fixed in 2.29.17
  6. Upgrade

    Upgrade Coder tailnet coordinator to a version that resolves this vulnerability.

    Fixed in 2.32.7
  7. Upgrade

    Upgrade Coder tailnet coordinator to a version that resolves this vulnerability.

    Fixed in 2.33.8
  8. Upgrade

    Upgrade Coder tailnet coordinator to a version that resolves this vulnerability.

    Fixed in 2.34.2
  9. Compensating control

    As a workaround (when unable to upgrade immediately), monitor coordinator logs for agents advertising unexpected `AllowedIPs` prefixes.

Event History

Jul 6, 2026
Advisory Published
via GitHub·08:58 PM
Data Sourced
via GitHub·08:58 PM
DescriptionSeverityWeaknessAffected Software
Jul 7, 2026
CVE Published
via MITRE·11:57 PM
Data Sourced
via MITRE·11:57 PM
DescriptionSeverityWeakness
Jul 8, 2026
Data Sourced
via NVD·12:16 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-55428?

The severity of CVE-2026-55428 is high, rated at 8.2.

2

How do I fix CVE-2026-55428?

To fix CVE-2026-55428, ensure adequate validation of agent-supplied AllowedIPs in the tailnet coordinator.

3

What type of vulnerability is CVE-2026-55428?

CVE-2026-55428 is a route hijacking vulnerability due to lack of validation of AllowedIPs.

4

Who is affected by CVE-2026-55428?

Users of the Coder software in version 2 are affected by CVE-2026-55428.

5

What impact does CVE-2026-55428 have?

CVE-2026-55428 can lead to unauthorized access through improper insertion of AllowedIPs into the WireGuard peer configuration.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203