Back

HIGH

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Published Jul 7, 2026

Description

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2, the tailnet coordinator validates that an agent's `Addresses` derive from its authenticated UUID but applies no equivalent check to `AllowedIPs`. The coordinator forwards agent-supplied `AllowedIPs` verbatim to tunnel peers which install them into the WireGuard peer configuration. The fix in versions 2.29.7, 2.32.7, 2.33.8, and 2.34.2 validates each `AllowedIPs` prefix against the authenticating agent's UUID just like `Addresses`. As a workaround, monitor coordinator logs for agents advertising unexpected `AllowedIPs` prefixes.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jul 7, 2026
Updated Jul 8, 2026
Reserved Jun 16, 2026

CISA Vulnrichment

Updated Jul 8, 2026

NVD

Status Analyzed
Modified Jul 8, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Jul 7, 2026
Updated Jul 8, 2026