PT-2026-57173 · Cap Go · Cap-Go

·

CVE-2026-56329

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions Capgo versions prior to 12.128.2
Description An issue exists due to non-bijective decoding of double underscores to dots during preview hostname parsing. This allows attackers to register app IDs containing underscores that collide with the dotted app IDs of other tenants, leading to preview misrouting and denial of preview access for victim applications.
Recommendations Update to version 12.128.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56329
GHSA-76QQ-GG2P-PWWJ

Affected Products

Cap-Go