CVE-2026-56248

HIGH

Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy

Title source: cna
STIX 2.1

Description

Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries to the public.audit_logs endpoint using the public anon key consistently trigger statement timeouts (PostgREST error 57014). Under concurrency, this exhausts database resources and causes cascading HTTP 500 failures on unrelated endpoints (e.g. /orgs), resulting in an application-layer denial of service.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-5vgv-rqj5-5748)
https://github.com/Cap-go/capgo/security/advisories/GHSA-5vgv-rqj5-5748
Third Party Advisory third-party-advisory
VulnCheck Advisory: Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy
https://www.vulncheck.com/advisories/capgo-unauthenticated-denial-of-service-via-audit-logs-rls-policy

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 28.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (2)
Cap-go/capgo < 12.128.12
Cap-go/capgo 12.128.12
Published Jun 23, 2026
Tracked Since Jun 23, 2026