CVE-2026-55435: Suspended Coder users retain access to AI Bridge LLM proxy endpoints

Published Jul 6, 2026
·
Updated

Summary

AI Bridge proxy endpoints authenticate via Server.IsAuthorized in coderd/aibridgedserver, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working.

Note: Practical impact is limited to already-issued API keys of suspended users until those keys are deleted.

Impact

A suspended user with a previously issued long-lived token could continue calling AI Bridge LLM proxy endpoints, consuming paid provider resources billed to the deployment and, if injected MCP tools are enabled, invoking those tools. Access persists until the token expires, which may be months after suspension.

Patches

The fix makes AI Bridge authorization reject non-active users like the standard API key middleware. AI Bridge was introduced in v2.30.0. The v2.29 ESR line is not affected.

The fix is available in the following releases:

| Release line | Patched version | |---|---| | 2.34 | v2.34.2 | | 2.33 | v2.33.8 | | 2.32 | v2.32.7 |

Workarounds

On suspension, delete the user's API keys via DELETE /api/v2/users/{user}/keys.

Resources

- Fix: #26173

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22446) for independently disclosing this issue!

Other sources

Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, AI Bridge proxy endpoints authenticate via Server.IsAuthorized in coderd/aibridgedserver, which validates key format, expiry, secret and deleted or system users but does not check whether the account is suspended. Because suspension does not revoke existing API keys, a suspended user's unexpired token keeps working. Practical impact is limited to already-issued API keys of suspended users until those keys are deleted. Versions 2.32.7, 2.33.8, and 2.34.2 patch the issue. As a workaround, on suspension, delete the user's API keys via DELETE /api/v2/users/{user}/keys.

MITRE

Affected Software

6 affected componentsFixes available
go/github.com/coder/coder/v2>=2.30.0<2.32.7
2.32.7
go/github.com/coder/coder/v2>=2.33.0<2.33.8
2.33.8
go/github.com/coder/coder/v2>=2.34.0<2.34.2
2.34.2
Coder Coder Go>=2.30.0<2.32.7
Coder Coder Go>=2.33.0<2.33.8
Coder Coder Go>=2.34.0<2.34.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.32.7
  2. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.33.8
  3. Upgrade

    Upgrade go/github.com/coder/coder/v2 to a version that resolves this vulnerability.

    Fixed in 2.34.2
  4. Upgrade

    Upgrade Coder AI Bridge (aibridgedserver) to a version that resolves this vulnerability.

    Fixed in 2.32.7Patch #26173
  5. Upgrade

    Upgrade Coder AI Bridge (aibridgedserver) to a version that resolves this vulnerability.

    Fixed in 2.33.8Patch #26173
  6. Upgrade

    Upgrade Coder AI Bridge (aibridgedserver) to a version that resolves this vulnerability.

    Fixed in 2.34.2Patch #26173
  7. Configuration

    As a workaround, when a user is suspended, delete their long-lived API keys by running DELETE /api/v2/users/{user}/keys so previously issued tokens can no longer call AI Bridge proxy endpoints.

    Coder API Delete suspended user API keys = DELETE /api/v2/users/{user}/keys

Event History

Jul 6, 2026
Advisory Published
via GitHub·09:11 PM
Data Sourced
via GitHub·09:11 PM
DescriptionSeverityWeaknessAffected Software
Jul 7, 2026
CVE Published
via MITRE·05:37 PM
Data Sourced
via MITRE·05:37 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-55435?

CVE-2026-55435 has a medium severity rating of 5.4.

2

How do I fix CVE-2026-55435?

To fix CVE-2026-55435, ensure that suspended users are properly disabled from accessing proxy endpoints by revoking their API keys.

3

What are the potential risks associated with CVE-2026-55435?

The risk associated with CVE-2026-55435 is that suspended users retain unauthorized access due to unrevoked API keys.

4

Which software is affected by CVE-2026-55435?

CVE-2026-55435 affects the Coder Go software, specifically the AI Bridge proxy endpoints.

5

What authentication flaw is present in CVE-2026-55435?

CVE-2026-55435 presents an authentication flaw where suspended users can still authenticate to the AI Bridge LLM proxy due to a lack of suspension checks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203