Coder's workspace app proxy trusts the client-controllable X-Forwarded-Host header to decide which app to route a request to, but still authorizes the request using the wildcard-scoped session cookie the browser auto-attaches — a textbook confused-deputy flaw. If your deployment has subdomain app routing enabled and no upstream proxy stripping that header, an attacker who controls any shared workspace app can trick a victim into visiting it and then read back responses from the victim's private app. There's no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template, and the CVSS vector (AC:H, UI:R, PR:L) reflects that real exploitation needs specific config plus a lured victim — so this isn't an urgent breaking-alert item, but with 5,435 downstream dependents the blast radius across multi-tenant Coder fleets is real. Patch to 2.34.2/2.33.8/2.32.7/2.29.17 now, and if you can't patch immediately, configure your reverse proxy to strip or overwrite X-Forwarded-Host on untrusted requests as an interim control.
What is the risk?
Medium severity (CVSS 5.8) is appropriate: confidentiality impact is high (S:C, C:H) but integrity/availability are unaffected, and exploitation requires several conditions to align simultaneously — wildcard subdomain app routing enabled, an upstream proxy that does not strip X-Forwarded-Host, low-privilege attacker access to a shared app, and victim user interaction. No EPSS score, no CISA KEV entry, no public PoC/exploit, and no Nuclei template exist, indicating exploitation is currently theoretical/researcher-discovered (credited to Anthropic's Security Team) rather than observed in the wild. The main risk driver is scale: Coder has 5,435 downstream dependents, and any multi-tenant or shared-workspace deployment with wildcard routing enabled is exposed until patched or mitigated.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Anthropic Python | go | >= 2.34.0, < 2.34.2 | 2.34.2 |
Do you use Anthropic Python? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR). If patching is delayed, apply the documented workaround: place an upstream reverse proxy that strips or overwrites X-Forwarded-Host on all untrusted/client-facing requests before they reach the Coder app proxy. As an additional interim control, consider disabling wildcard subdomain app routing or restricting who can create/share workspace apps until patched. For detection, audit your ingress/reverse-proxy configuration to confirm X-Forwarded-Host is not passed through unmodified from clients, and review access logs for requests where the Host header and any forwarded-host value diverge on workspace app subdomains.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-55430?
Coder's workspace app proxy trusts the client-controllable X-Forwarded-Host header to decide which app to route a request to, but still authorizes the request using the wildcard-scoped session cookie the browser auto-attaches — a textbook confused-deputy flaw. If your deployment has subdomain app routing enabled and no upstream proxy stripping that header, an attacker who controls any shared workspace app can trick a victim into visiting it and then read back responses from the victim's private app. There's no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template, and the CVSS vector (AC:H, UI:R, PR:L) reflects that real exploitation needs specific config plus a lured victim — so this isn't an urgent breaking-alert item, but with 5,435 downstream dependents the blast radius across multi-tenant Coder fleets is real. Patch to 2.34.2/2.33.8/2.32.7/2.29.17 now, and if you can't patch immediately, configure your reverse proxy to strip or overwrite X-Forwarded-Host on untrusted requests as an interim control.
Is CVE-2026-55430 actively exploited?
No confirmed active exploitation of CVE-2026-55430 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-55430?
Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR). If patching is delayed, apply the documented workaround: place an upstream reverse proxy that strips or overwrites X-Forwarded-Host on all untrusted/client-facing requests before they reach the Coder app proxy. As an additional interim control, consider disabling wildcard subdomain app routing or restricting who can create/share workspace apps until patched. For detection, audit your ingress/reverse-proxy configuration to confirm X-Forwarded-Host is not passed through unmodified from clients, and review access logs for requests where the Host header and any forwarded-host value diverge on workspace app subdomains.
What systems are affected by CVE-2026-55430?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, AI development sandboxes / cloud dev environments, multi-tenant workspace platforms.
What is the CVSS score for CVE-2026-55430?
CVE-2026-55430 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.21%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0011.003 Malicious Link AML.T0049 Exploit Public-Facing Application Compliance Controls Affected
What are the technical details?
Original Advisory
### Summary The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `fetch()` calls. > **Note:** Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip `X-Forwarded-Host`. ### Impact App session cookies are scoped to the wildcard parent domain so the browser attaches them to any app subdomain. An attacker who controls a shared workspace app can serve JavaScript that sends same-site requests with a forged `X-Forwarded-Host` pointing at a victim's private app. The server routes by the attacker-controlled header but authorizes with the victim's cookie which lets the attacker read the victim's private app responses. Subdomain app routing must be enabled and no upstream proxy may strip `X-Forwarded-Host`. ### Patches The fix trusts `X-Forwarded-Host` only from configured trusted proxies and otherwise resolves the routing host from the verified request host. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds Place an upstream reverse proxy that strips or overwrites `X-Forwarded-Host` on untrusted requests. ### Resources - Fix: #26204 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22435) for independently disclosing this issue!
Exploitation Scenario
An organization runs Coder with wildcard subdomain app routing enabled for its AI engineering team's cloud dev sandboxes, and its edge proxy does not strip X-Forwarded-Host. An attacker with access to their own (or a compromised) shared workspace app hosts malicious JavaScript there and shares the link with a colleague, or gets it surfaced via an internal app gallery. The victim, already authenticated with a session cookie scoped to the shared parent domain, opens the attacker's app. The malicious script fires same-site fetch() calls with X-Forwarded-Host forged to the victim's private app subdomain; the untrusted proxy routes the request there, but authorization still relies on the cookie the browser auto-attaches — the victim's own credential. The attacker's page reads back the response, exfiltrating whatever the victim's private app (e.g., an AI agent's workspace UI, notebook, or terminal proxy) rendered, without ever needing the victim's actual credentials.
Weaknesses (CWE)
CWE-345 Insufficient Verification of Data Authenticity
Primary
CWE-441 Unintended Proxy or Intermediary ('Confused Deputy')
Primary
CWE-345 Insufficient Verification of Data Authenticity CWE-441 Unintended Proxy or Intermediary ('Confused Deputy') CWE-345 — Insufficient Verification of Data Authenticity: The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N References
Timeline
Related Vulnerabilities
CVE-2026-27775 8.8 Gitea: cached permission check allows repo takeover
Same package: anthropic CVE-2026-54449 8.8 LangBot: RCE via arbitrary STDIO MCP command
Same package: anthropic CVE-2026-7574 8.7 Claude Desktop: VM integrity bypass enables RCE
Same package: anthropic CVE-2026-55429 8.7 Coder: cross-workspace agent hijack via app ID reuse
Same package: anthropic CVE-2026-67428 8.5 Flyto2 Core: SSRF via unvalidated URLs in agent tools
Same package: anthropic