CVE-2026-56329 Details
Description
Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs, causing preview misrouting and denial of preview access for victim applications.
A cross-tenant preview namespace collision vulnerability has been identified in Capgo versions prior to 12.128.2. This vulnerability arises from a lossy decoding process that translates double underscores into dots when parsing preview hostnames. As a result, attackers can create app IDs with underscores that interfere with other tenants' app IDs, leading to misrouted preview requests and denied access for affected applications.
Users can update to Capgo version 12.128.2 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-76qq-gg2p-pwwj | CISA-ADP | AdvisoryTechnical AnalysisVendor |
| https://github.com/Cap-go/capgo/security/advisories/GHSA-76qq-gg2p-pwwj | [email protected] | AdvisoryTechnical AnalysisVendor |
| https://www.vulncheck.com/advisories/capgo-cross-tenant-preview-namespace-collision-via-non-bijective-underscore-decoding | [email protected] | AdvisoryVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-436 | Interpretation Conflict | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Capgo | < 12.128.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion