CVE-2026-55438
- EPSS 0.15%
- Veröffentlicht 08.07.2026 00:31:20
- Zuletzt bearbeitet 08.07.2026 19:38:38
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, Coder's subdomain-based workspace app proxy allowed the same-owner CORS check to be bypassed. When a workspa...
CVE-2026-55437
- EPSS 0.18%
- Veröffentlicht 08.07.2026 00:29:18
- Zuletzt bearbeitet 08.07.2026 19:38:48
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.17, 2.32.7, 2.33.8, and 2.34.2, the `AgentLogLine` dashboard component instantiated `ansi-to-html` without `escapeXML: true` and inserted th...
CVE-2026-55436
- EPSS 0.16%
- Veröffentlicht 08.07.2026 00:26:13
- Zuletzt bearbeitet 08.07.2026 19:39:30
Coder allows organizations to provision remote development environments via Terraform. Starting in version 2.30.0 and prior to versions 2.32.7, 2.33.8, and 2.34.2, the AI Bridge Proxy (`aibridgeproxyd`) created a goproxy server whose default transpor...
CVE-2026-55433
- EPSS 0.22%
- Veröffentlicht 08.07.2026 00:22:36
- Zuletzt bearbeitet 08.07.2026 19:39:45
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the devcontainer recreate endpoint relied on route middleware that checked only `ActionRead` on the workspace...
CVE-2026-55432
- EPSS 0.18%
- Veröffentlicht 08.07.2026 00:20:24
- Zuletzt bearbeitet 08.07.2026 19:40:36
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharin...
CVE-2026-55431
- EPSS 0.18%
- Veröffentlicht 08.07.2026 00:10:49
- Zuletzt bearbeitet 08.07.2026 19:42:45
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder open app` opens external workspace-app URLs without validating the scheme or host. When an external ap...
CVE-2026-55430
- EPSS 0.14%
- Veröffentlicht 08.07.2026 00:03:29
- Zuletzt bearbeitet 08.07.2026 19:43:14
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-H...
CVE-2026-55429
- EPSS 0.29%
- Veröffentlicht 08.07.2026 00:00:33
- Zuletzt bearbeitet 08.07.2026 19:43:31
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `UpsertWorkspaceApp` overwrites an existing app's `agent_id` on a primary-key conflict and `insertAgentApp` a...
CVE-2026-55428
- EPSS 0.25%
- Veröffentlicht 07.07.2026 23:57:45
- Zuletzt bearbeitet 08.07.2026 19:44:06
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies ...
CVE-2026-55427
- EPSS 0.27%
- Veröffentlicht 07.07.2026 23:55:26
- Zuletzt bearbeitet 08.07.2026 19:44:24
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, `coder config-ssh` wrote server-supplied SSH settings (`HostnameSuffix`, `SSHConfigOptions`) into the user's ...