CVE-2026-45796
medium
CVSS v3
โ
CVSS v4 NEW
โ
VIR risk
5.5
Description
Coder: Unauthenticated SSRF via Azure Instance Identity Endpoint
Predictions
Exploit likelihood
30%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | github.com/coder/coder/v2 | >=2.33.0-rc.0,<2.33.3 | 2.33.3 |
| Go | github.com/coder/coder/v2 | >=2.32.0-rc.0,<2.32.2 | 2.32.2 |
| Go | github.com/coder/coder/v2 | >=2.31.0,<2.31.12 | 2.31.12 |
| Go | github.com/coder/coder/v2 | >=2.30.0,<2.30.8 | 2.30.8 |
| Go | github.com/coder/coder/v2 | >=2.29.0,<2.29.13 | 2.29.13 |
| Go | github.com/coder/coder/v2 | <2.24.5 | 2.24.5 |
| Go | github.com/coder/coder | <=0.27.3 | |
| GO | github.com/coder/coder | <= 0.27.3 | |
| GO | github.com/coder/coder/v2 | < 2.24.5 | 2.24.5 |
| GO | github.com/coder/coder/v2 | >= 2.29.0, < 2.29.13 | 2.29.13 |
| GO | github.com/coder/coder/v2 | >= 2.30.0, < 2.30.8 | 2.30.8 |
| GO | github.com/coder/coder/v2 | >= 2.31.0, < 2.31.12 | 2.31.12 |
| GO | github.com/coder/coder/v2 | >= 2.32.0-rc.0, < 2.32.2 | 2.32.2 |
| GO | github.com/coder/coder/v2 | >= 2.33.0-rc.0, < 2.33.3 | 2.33.3 |
References
- https://github.com/coder/coder/security/advisories/GHSA-686c-7vgv-v3fx
- https://github.com/coder/coder/pull/25274
- https://github.com/coder/coder/commit/57b11d405f17492aa789d4b9ff33366f961a37f8
- https://github.com/coder/coder
- https://github.com/coder/coder/releases/tag/v2.24.5
- https://github.com/coder/coder/releases/tag/v2.29.13
- https://github.com/coder/coder/releases/tag/v2.30.8
- https://github.com/coder/coder/releases/tag/v2.31.12
- https://github.com/coder/coder/releases/tag/v2.32.2
- https://github.com/coder/coder/releases/tag/v2.33.3
- https://github.com/advisories/GHSA-686c-7vgv-v3fx
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.