CVE-2026-55430: Coder: X-Forwarded-Host spoof leaks victim app data

GHSA-5g4w-3vw9-478w MEDIUM
Published July 6, 2026
CISO Take

Coder's workspace app proxy trusts the client-controllable X-Forwarded-Host header to decide which app to route a request to, but still authorizes the request using the wildcard-scoped session cookie the browser auto-attaches — a textbook confused-deputy flaw. If your deployment has subdomain app routing enabled and no upstream proxy stripping that header, an attacker who controls any shared workspace app can trick a victim into visiting it and then read back responses from the victim's private app. There's no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template, and the CVSS vector (AC:H, UI:R, PR:L) reflects that real exploitation needs specific config plus a lured victim — so this isn't an urgent breaking-alert item, but with 5,435 downstream dependents the blast radius across multi-tenant Coder fleets is real. Patch to 2.34.2/2.33.8/2.32.7/2.29.17 now, and if you can't patch immediately, configure your reverse proxy to strip or overwrite X-Forwarded-Host on untrusted requests as an interim control.

Sources: NVD GitHub Advisory ATLAS

What is the risk?

Medium severity (CVSS 5.8) is appropriate: confidentiality impact is high (S:C, C:H) but integrity/availability are unaffected, and exploitation requires several conditions to align simultaneously — wildcard subdomain app routing enabled, an upstream proxy that does not strip X-Forwarded-Host, low-privilege attacker access to a shared app, and victim user interaction. No EPSS score, no CISA KEV entry, no public PoC/exploit, and no Nuclei template exist, indicating exploitation is currently theoretical/researcher-discovered (credited to Anthropic's Security Team) rather than observed in the wild. The main risk driver is scale: Coder has 5,435 downstream dependents, and any multi-tenant or shared-workspace deployment with wildcard routing enabled is exposed until patched or mitigated.

How does the attack unfold?

Stage Capabilities
Attacker deploys or gains access to a shared workspace app on a Coder deployment with wildcard subdomain app routing enabled, hosting malicious client-side JavaScript.
AML.T0079
Victim Lure
Attacker convinces a victim who has an active session on their own private app to open the attacker's shared app in the same browser.
AML.T0011.003
Header Spoofing Exploitation
The malicious page issues fetch() requests forging X-Forwarded-Host to the victim's private app; the untrusted proxy routes there while the browser auto-attaches the victim's wildcard-scoped session cookie.
AML.T0049
Confidentiality Impact
The attacker's script reads back the victim's private app response, exfiltrating data intended only for the victim in a classic confused-deputy disclosure.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
Anthropic Python go >= 2.34.0, < 2.34.2 2.34.2
3.8K 5.2K dependents Pushed 4d ago 90% patched ~11d to patch Full package profile →

Do you use Anthropic Python? You're affected.

How severe is it?

CVSS 3.1
5.8 / 10
EPSS
0.2%
chance of exploitation in 30 days
Higher than 11% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC High
PR Low
UI Required
S Changed
C High
I None
A None

What should I do?

1 step
  1. Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR). If patching is delayed, apply the documented workaround: place an upstream reverse proxy that strips or overwrites X-Forwarded-Host on all untrusted/client-facing requests before they reach the Coder app proxy. As an additional interim control, consider disabling wildcard subdomain app routing or restricting who can create/share workspace apps until patched. For detection, audit your ingress/reverse-proxy configuration to confirm X-Forwarded-Host is not passed through unmodified from clients, and review access logs for requests where the Host header and any forwarded-host value diverge on workspace app subdomains.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
NIST AI RMF
MANAGE 4.1 - Risks and benefits from third-party resources are regularly monitored

Frequently Asked Questions

What is CVE-2026-55430?

Coder's workspace app proxy trusts the client-controllable X-Forwarded-Host header to decide which app to route a request to, but still authorizes the request using the wildcard-scoped session cookie the browser auto-attaches — a textbook confused-deputy flaw. If your deployment has subdomain app routing enabled and no upstream proxy stripping that header, an attacker who controls any shared workspace app can trick a victim into visiting it and then read back responses from the victim's private app. There's no CISA KEV listing, no EPSS score, and no public exploit or Nuclei template, and the CVSS vector (AC:H, UI:R, PR:L) reflects that real exploitation needs specific config plus a lured victim — so this isn't an urgent breaking-alert item, but with 5,435 downstream dependents the blast radius across multi-tenant Coder fleets is real. Patch to 2.34.2/2.33.8/2.32.7/2.29.17 now, and if you can't patch immediately, configure your reverse proxy to strip or overwrite X-Forwarded-Host on untrusted requests as an interim control.

Is CVE-2026-55430 actively exploited?

No confirmed active exploitation of CVE-2026-55430 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-55430?

Patch immediately to the version matching your release line: 2.34.2, 2.33.8, 2.32.7, or 2.29.17 (ESR). If patching is delayed, apply the documented workaround: place an upstream reverse proxy that strips or overwrites X-Forwarded-Host on all untrusted/client-facing requests before they reach the Coder app proxy. As an additional interim control, consider disabling wildcard subdomain app routing or restricting who can create/share workspace apps until patched. For detection, audit your ingress/reverse-proxy configuration to confirm X-Forwarded-Host is not passed through unmodified from clients, and review access logs for requests where the Host header and any forwarded-host value diverge on workspace app subdomains.

What systems are affected by CVE-2026-55430?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, AI development sandboxes / cloud dev environments, multi-tenant workspace platforms.

What is the CVSS score for CVE-2026-55430?

CVE-2026-55430 has a CVSS v3.1 base score of 5.8 (MEDIUM). The EPSS exploitation probability is 0.21%.

What is the AI security impact?

Affected AI Architectures

agent frameworksAI development sandboxes / cloud dev environmentsmulti-tenant workspace platforms

MITRE ATLAS Techniques

AML.T0011.003 Malicious Link
AML.T0049 Exploit Public-Facing Application

Compliance Controls Affected

EU AI Act: Article 15
NIST AI RMF: MANAGE 4.1

What are the technical details?

Original Advisory

### Summary The workspace app proxy resolves the target app from `httpapi.RequestHost()` which prefers the `X-Forwarded-Host` header over the real `Host` header. No middleware strips `X-Forwarded-Host` before routing and the header is not browser-forbidden so client-side JavaScript can set it on `fetch()` calls. > **Note:** Practical exploitation requires subdomain app routing (wildcard hostname) enabled, a victim who visits the attacker's shared app and a deployment whose upstream proxy does not strip `X-Forwarded-Host`. ### Impact App session cookies are scoped to the wildcard parent domain so the browser attaches them to any app subdomain. An attacker who controls a shared workspace app can serve JavaScript that sends same-site requests with a forged `X-Forwarded-Host` pointing at a victim's private app. The server routes by the attacker-controlled header but authorizes with the victim's cookie which lets the attacker read the victim's private app responses. Subdomain app routing must be enabled and no upstream proxy may strip `X-Forwarded-Host`. ### Patches The fix trusts `X-Forwarded-Host` only from configured trusted proxies and otherwise resolves the routing host from the verified request host. The fix was backported to all supported release lines: | Release line | Patched version | |---|---| | 2.34 | [v2.34.2](https://github.com/coder/coder/releases/tag/v2.34.2) | | 2.33 | [v2.33.8](https://github.com/coder/coder/releases/tag/v2.33.8) | | 2.32 | [v2.32.7](https://github.com/coder/coder/releases/tag/v2.32.7) | | 2.29 (ESR) | [v2.29.17](https://github.com/coder/coder/releases/tag/v2.29.17) | ### Workarounds Place an upstream reverse proxy that strips or overwrites `X-Forwarded-Host` on untrusted requests. ### Resources - Fix: #26204 ### Credits Coder would like to thank Anthropic's Security Team (ANT-2026-22435) for independently disclosing this issue!

Exploitation Scenario

An organization runs Coder with wildcard subdomain app routing enabled for its AI engineering team's cloud dev sandboxes, and its edge proxy does not strip X-Forwarded-Host. An attacker with access to their own (or a compromised) shared workspace app hosts malicious JavaScript there and shares the link with a colleague, or gets it surfaced via an internal app gallery. The victim, already authenticated with a session cookie scoped to the shared parent domain, opens the attacker's app. The malicious script fires same-site fetch() calls with X-Forwarded-Host forged to the victim's private app subdomain; the untrusted proxy routes the request there, but authorization still relies on the cookie the browser auto-attaches — the victim's own credential. The attacker's page reads back the response, exfiltrating whatever the victim's private app (e.g., an AI agent's workspace UI, notebook, or terminal proxy) rendered, without ever needing the victim's actual credentials.

Weaknesses (CWE)

CWE-345 — Insufficient Verification of Data Authenticity: The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N

Timeline

Published
July 6, 2026
Last Modified
July 8, 2026
First Seen
July 7, 2026

Related Vulnerabilities