Improper Certificate Validation Affecting github.com/coder/coder/v2/enterprise/aibridgeproxyd package, versions >=2.30.0 <2.32.7>=2.33.0 <2.33.8>=2.34.0 <2.34.2


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCODERCODERV2ENTERPRISEAIBRIDGEPROXYD-17872196
  • published6 Jul 2026
  • disclosed6 Jul 2026
  • creditUnknown

Introduced: 6 Jul 2026

CVE-2026-55436  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade github.com/coder/coder/v2/enterprise/aibridgeproxyd to version 2.32.7, 2.33.8, 2.34.2 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation in the aibridgeproxyd process when the default transport is configured with InsecureSkipVerify: true, causing outbound HTTPS connections to accept any TLS certificate. An attacker can intercept sensitive information such as session tokens, API keys, and request/response bodies by performing a man-in-the-middle attack between the proxy and the server. This is only exploitable if the attacker is positioned on the network path between the proxy and the server; deployments using loopback or mTLS are not affected.

Workaround

This vulnerability can be mitigated by ensuring the access URL uses a trusted certificate and securing the network path between the proxy and the server (e.g., via loopback or mTLS).

CVSS Base Scores

version 4.0
version 3.1