CVE-2026-55430: Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

Published Jul 6, 2026
·
Updated

Summary

The workspace app proxy resolves the target app from httpapi.RequestHost() which prefers the X-Forwarded-Host header over the real Host header. No middleware strips X-Forwarded-Host before routing and the header is not browser-forbidden so client-side JavaScript can set it on fetch() calls.

Note: Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip X-Forwarded-Host.

Impact

App session cookies are scoped to the wildcard parent domain so the browser attaches them to any app subdomain. An attacker who controls a shared workspace app can serve JavaScript that sends same-site requests with a forged X-Forwarded-Host pointing at a victim's private app. The server routes by the attacker-controlled header but authorizes with the victim's cookie which lets the attacker read the victim's private app responses. Subdomain app routing must be enabled and no upstream proxy may strip X-Forwarded-Host.

Patches

The fix trusts X-Forwarded-Host only from configured trusted proxies and otherwise resolves the routing host from the verified request host.

The fix was backported to all supported release lines:

| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 | | 2.29 (ESR) | v2.29.17 |

Workarounds

Place an upstream reverse proxy that strips or overwrites X-Forwarded-Host on untrusted requests.

Resources

- Fix: #26204

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22435) for independently disclosing this issue!

Other sources

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from httpapi.RequestHost() which prefers the X-Forwarded-Host header over the real Host header. No middleware strips X-Forwarded-Host before routing and the header is not browser-forbidden so client-side JavaScript can set it on fetch() calls. Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip X-Forwarded-Host. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 trusts X-Forwarded-Host only from configured trusted proxies and otherwise resolves the routing host from the verified request host. As a workaround, place an upstream reverse proxy that strips or overwrites X-Forwarded-Host on untrusted requests.

MITRE

Affected Software

8 affected componentsFixes available
go/github.com/coder/coder/v2<2.29.17
2.29.17
go/github.com/coder/coder/v2>=2.30.0<2.32.7
2.32.7
go/github.com/coder/coder/v2>=2.33.0<2.33.8
2.33.8
go/github.com/coder/coder/v2>=2.34.0<2.34.2
2.34.2
Coder Coder Go<2.29.17
Coder Coder Go>=2.30.0<2.32.7
Coder Coder Go>=2.33.0<2.33.8
Coder Coder Go>=2.34.0<2.34.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.29.17
  2. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.32.7
  3. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.33.8
  4. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.34.2
  5. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.29.17
  6. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.32.7
  7. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.33.8
  8. Upgrade

    Upgrade coder to a version that resolves this vulnerability.

    Fixed in 2.34.2
  9. Compensating control

    Place an upstream reverse proxy in front of Coder that strips or overwrites the `X-Forwarded-Host` header on untrusted requests (so untrusted clients cannot control routing via `X-Forwarded-Host`).

Event History

Jul 6, 2026
Advisory Published
via GitHub·09:05 PM
Data Sourced
via GitHub·09:05 PM
DescriptionSeverityWeaknessAffected Software
Jul 8, 2026
CVE Published
via MITRE·12:03 AM
Data Sourced
via MITRE·12:03 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-55430?

The severity of CVE-2026-55430 is medium with a score of 6.8.

2

How do I fix CVE-2026-55430?

To fix CVE-2026-55430, ensure that your app middleware strips the `X-Forwarded-Host` header before routing.

3

What risks are associated with CVE-2026-55430?

CVE-2026-55430 may allow unauthorized cross-app data access due to trust in the unauthenticated `X-Forwarded-Host` header.

4

Which software is affected by CVE-2026-55430?

CVE-2026-55430 affects the Coder workspace app running on Go.

5

When was CVE-2026-55430 published?

CVE-2026-55430 was published on July 6, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203