CVE-2026-63443
- Gepubliceerd15 sep 2026
Beschrijving
Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the workspace agent HTTP API port 4. An authenticated user who controls a modified workspace agent and knows another online agent's UUID can derive the victim's tailnet address and redirect control-plane requests to that agent. HTTP 301, 302, and 303 redirects can redirect read requests, while HTTP 307 and 308 preserve replayable write and process-start requests. The redirected workspace agent file APIs can read or write files as the victim workspace user, and affected versions exposing the workspace agent process API can execute commands after a redirected file write, crossing workspace and tenant boundaries. This issue is fixed in versions 2.29.19, 2.32.9, 2.33.10, and 2.34.4.
CVSS 3.1-ontleding
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LHerstel
Er is geen opgeloste versie vastgelegd in de NVD-data. Raadpleeg het leveranciersadvies voor de laatste richtlijnen.
Referenties
- https://github.com/coder/coder/commit/2312b67bc52c4e314c18c4b4be5dcf5500c94ad7
- https://github.com/coder/coder/commit/812549d671d0f5a0b45adcee860d37b70aaddccd
- https://github.com/coder/coder/commit/ec3ba84c0002f47dd979c073cde1ab345acbaea5
- https://github.com/coder/coder/commit/eeb2624549ddb85538e493af3e678fdb185a809f
- https://github.com/coder/coder/commit/f8bdec5add4711650d5bfb6ff93d0cc9d7821c81
- https://github.com/coder/coder/pull/26600
- https://github.com/coder/coder/pull/26611
- https://github.com/coder/coder/pull/26612
- https://github.com/coder/coder/pull/26613
- https://github.com/coder/coder/pull/26622
en nog 5 referenties
Gerelateerde CVE's
Recente ernstige kwetsbaarheden met hetzelfde zwakhedentype.
Veelgestelde vragen
Wordt CVE-2026-63443 actief misbruikt?
CVE-2026-63443 staat niet in de CISA KEV-catalogus.
Hoe ernstig is CVE-2026-63443?
CVE-2026-63443 heeft een CVSS 3.1-basisscore van 8.3, beoordeeld als high.
Hoe verhelp ik CVE-2026-63443?
Pas de patch of het advies van de leverancier toe en controleer dat er geen getroffen versies meer op uw apparaten staan.
Hoe Secuno hiermee omgaat
Secuno correleert kwetsbaarheden zoals CVE-2026-63443 dagelijks tegen de werkelijke software-inventaris op elk beheerd apparaat. In plaats van een statische ernst wordt elke match in context gescoord: exploitbeschikbaarheid, EPSS, de blootstelling van het asset en bedrijfskriticiteit bepalen de prioriteit. Als een getroffen versie ergens in uw portfolio aanwezig is, verschijnt die automatisch met een geprioriteerd hersteltraject.
Data uit de NVD, CISA KEV-catalogus en FIRST EPSS. CVSS 3.1-basisscore getoond indien beschikbaar.