PT-2026-51407 · Cap Go · Cap-Go

·

CVE-2026-56306

·

Published

2026-06-22

·

Updated

2026-06-23

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description A weak parsing issue exists in the x-limited-key-id header. Remote attackers can bypass subkey enforcement by submitting duplicate headers, zero, or malformed values that result in falsy values or NaN (Not-a-Number, a value representing an undefined or unrepresentable numerical result). This allows the attacker to disable limited key scoping and execute requests using the main API key context instead of the restricted subkey permissions.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56306
GHSA-42VV-8J94-24WJ

Affected Products

Cap-Go