« Volver al listado

Capgo

Capgo Cap-go: vulnerabilidades y CVE

Capgo Cap-go tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses9
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-56296Media (6.9)0.36%—11 jul 2026
Cap-go before 12.128.2 contains an information disclosure vulnerability in the public.transfer_app RPC function that returns distinct error messages for existing versus non-existing app IDs. Unauthenticated attackers…
CVE-2026-56310Media (5.3)0.30%—24 jun 2026
Cap-go before 12.128.2 contains an authorization bypass vulnerability in the GET /organization/members endpoint that allows org-limited API keys to bypass limited_to_orgs restrictions. Attackers with org-limited API…
CVE-2026-56280Alta (7.1)0.37%—22 jun 2026
Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE…
CVE-2026-56221Alta (7.1)0.38%—22 jun 2026
Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values from API request bodies are interpolated directly into SQL query strings without sanitization or…
CVE-2026-56316Media (6.9)0.41%—21 jun 2026
Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through observable response…
CVE-2026-56307Media (5.3)0.37%—20 jun 2026
Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later…
CVE-2026-56081Crítica (9.3)0.57%—19 jun 2026
Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication…
CVE-2026-56073Crítica (9.3)0.27%—19 jun 2026
Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification…
CVE-2026-53981Alta (7.2)0.48%—12 jun 2026
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email address without…

Otros productos de Capgo