Capgo
Capgo Cap-go: vulnerabilidades y CVE
Capgo Cap-go tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses9
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-56296 | Media (6.9) | 0.36% | — | 11 jul 2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers… |
| CVE-2026-56310 | Media (5.3) | 0.30% | — | 24 jun 2026 | Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API… |
| CVE-2026-56280 | Alta (7.1) | 0.37% | — | 22 jun 2026 | Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE… |
| CVE-2026-56221 | Alta (7.1) | 0.38% | — | 22 jun 2026 | Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API request bodies are interpolated directly into SQL query strings without sanitization or… |
| CVE-2026-56316 | Media (6.9) | 0.41% | — | 21 jun 2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through observable response… |
| CVE-2026-56307 | Media (5.3) | 0.37% | — | 20 jun 2026 | Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later… |
| CVE-2026-56081 | Crítica (9.3) | 0.57% | — | 19 jun 2026 | Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication… |
| CVE-2026-56073 | Crítica (9.3) | 0.27% | — | 19 jun 2026 | Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification… |
| CVE-2026-53981 | Alta (7.2) | 0.48% | — | 12 jun 2026 | Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without… |