Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator
Published Jul 7, 2026
8.2
HIGHCVSS 3.1
EPSS 0.40%
Description
Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates each `AllowedIPs` prefix against the authenticating agent's UUID just like `Addresses`. As a workaround, monitor coordinator logs for agents advertising unexpected `AllowedIPs` prefixes.
Affected products
-
Affected
- < 2.29.17
- ≥ 2.30.0, < 2.32.7
- ≥ 2.33.0, < 2.33.8
- ≥ 2.34.0, < 2.34.2
No data.
No Red Hat product state for this CVE.
github.com/coder/coder/v2
Go
Introduced 2.34.0 Fixed 2.34.2github.com/coder/coder/v2
Go
Introduced 2.33.0 Fixed 2.33.8github.com/coder/coder/v2
Go
Introduced 2.30.0 Fixed 2.32.7github.com/coder/coder/v2
Go
Introduced 0 Fixed 2.29.17github.com/coder/coder
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/coder/coder/v2 | 2.34.0 | 2.34.2 |
| Go | github.com/coder/coder/v2 | 2.33.0 | 2.33.8 |
| Go | github.com/coder/coder/v2 | 2.30.0 | 2.32.7 |
| Go | github.com/coder/coder/v2 | 0 | 2.29.17 |
| Go | github.com/coder/coder | 0 | not fixed |
Remediation
No remediation recorded yet.
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42134 Advisory
- https://github.com/advisories/GHSA-wrq8-fcv5-8hvp Advisory
- https://github.com/coder/coder/pull/26144 x_refsource_MISCIssue TrackingPatch
- https://github.com/coder/coder/releases/tag/v2.29.17 x_refsource_MISCRelease Notes
- https://github.com/coder/coder/releases/tag/v2.32.7 x_refsource_MISCRelease Notes
- https://github.com/coder/coder/releases/tag/v2.33.8 x_refsource_MISCRelease Notes
- https://github.com/coder/coder/releases/tag/v2.34.2 x_refsource_MISCRelease Notes
- https://github.com/coder/coder/security/advisories/GHSA-wrq8-fcv5-8hvp x_refsource_CONFIRMPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42134 | Advisory | |
| https://github.com/advisories/GHSA-wrq8-fcv5-8hvp | Advisory | |
| https://github.com/coder/coder/pull/26144 | x_refsource_MISCIssue TrackingPatch | |
| https://github.com/coder/coder/releases/tag/v2.29.17 | x_refsource_MISCRelease Notes | |
| https://github.com/coder/coder/releases/tag/v2.32.7 | x_refsource_MISCRelease Notes | |
| https://github.com/coder/coder/releases/tag/v2.33.8 | x_refsource_MISCRelease Notes | |
| https://github.com/coder/coder/releases/tag/v2.34.2 | x_refsource_MISCRelease Notes | |
| https://github.com/coder/coder/security/advisories/GHSA-wrq8-fcv5-8hvp | x_refsource_CONFIRMPatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub