Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐹
🐹 Go
Not in CISA KEV
MEDIUM severity

CVE-2026-55432 — v2

MEDIUMFix: coder/coder#26061

CVE-2026-55432 is a medium-severity (CVSS 5.4) CWE-862 vulnerability in github.com/coder/coder/v2. A fix is available for github.com/coder/coder/v2 — see the affected versions and patch details below.

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

Also known asGHSA-x9qq-2qh5-8rxfGO-2026-5926
Published
Updated
Affected
4 pkgs
Patched
4 / 4
Exploits
None indexed
Exploitation data as of Oct 3, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for CVE-2026-55432.

EPSS Exploitation Probability

via FIRST.org ↗
0.3%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs22th percentile — riskier than 22% of all scored CVEsHighest risk
0.00%0.27%0.54%0.82%0.3%0.3%Sep 26Oct 26

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

CVE-2026-55432 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 382,574 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

4 pkgs affected
🐹github.com/coder/coder/v2🐹github.com/coder/coder/v2🐹github.com/coder/coder/v2🐹github.com/coder/coder/v2

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects Go packages — download data is not available via public APIs for these ecosystems.

Description

Summary

The CreateSubAgent RPC did not validate a requested app sharing level against the template's MaxPortSharingLevel before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum.

Note: Exploitation requires the ability to register sub-agent apps in a workspace the attacker controls.

Impact

A workspace owner with an agent token could register a sub-agent app as PUBLIC even when the template's MaxPortSharingLevel was owner, exposing the app to unauthenticated users via the wildcard app domain. This affected only deployments using Enterprise port-sharing policy and wildcard app hostnames and required an authenticated workspace owner with an agent token.

Patches

The fix clamps the sub-agent app sharing level to the template's MaxPortSharingLevel.

The fix was backported to all supported release lines:

Release linePatched version
2.34v2.34.2
2.33v2.33.8
2.32v2.32.7
2.29 (ESR)v2.29.17

Workarounds

Disable wildcard app hostnames (CODER_WILDCARD_ACCESS_URL) to block subdomain-based app routing.

Resources

  • Fix: #26061

Credits

Coder would like to thank Anthropic's Security Team (ANT-2026-22452) for independently disclosing this issue!

Affected Packages

4 total 4 fixed
EcosystemPackageVulnerable rangeFix
🐹Gogithub.com/coder/coder/v2≥ 2.34.0&&< 2.34.22.34.2go get github.com/coder/coder/v2@v2.34.2
🐹Gogithub.com/coder/coder/v2≥ 2.33.0&&< 2.33.82.33.8go get github.com/coder/coder/v2@v2.33.8
🐹Gogithub.com/coder/coder/v2≥ 2.30.0&&< 2.32.72.32.7go get github.com/coder/coder/v2@v2.32.7
🐹Gogithub.com/coder/coder/v2all versions2.29.17go get github.com/coder/coder/v2@v2.29.17

Affected Products

1 product · 4 configurations
Application
codercoder
≥ 2.34.0 && < 2.34.2
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for github.com/coder/coder/v2, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update github.com/coder/coder/v2 to 2.34.2 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-55432 is resolved across your whole dependency graph.

  3. Workarounds

    Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used.

Frequently Asked Questions

### Summary The `CreateSubAgent` RPC did not validate a requested app sharing level against the template's `MaxPortSharingLevel` before persisting workspace apps, letting a workspace owner exceed the administrator's configured maximum. > **Note:** Exploitation requires the ability to register sub-agent apps in a workspace the attacker controls. ### Impact A workspace owner with an agent token could register a sub-agent app as `PUBLIC` even when the template's `MaxPortSharingLevel` was `owner`, exposing the app to unauthenticated users via the wildcard app domain. This affected only deploym
O3 Security · Impact-Aware SCA

Is CVE-2026-55432 in your dependencies?

Find it across Go, including transitive dependencies.

CVE-2026-55432: v2 — Fixed in 2.34.2 | O3 Security