CVE-2026-56328

MEDIUM

Capgo < 12.128.2 - Public Channel Release Routing Integrity Issue

Title source: manual
STIX 2.1

Description

Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly resolve to a single hidden winner channel. An authorized app or channel manager can create ambiguous default update state and silently influence which bundle unnamed clients receive, breaking release routing integrity and predictability.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-3cmp-pm5x-8464)
https://github.com/Cap-go/capgo/security/advisories/GHSA-3cmp-pm5x-8464
Third Party Advisory third-party-advisory
VulnCheck Advisory: Capgo - Integrity Issue in Release Routing via Multiple Public Channels
https://www.vulncheck.com/advisories/capgo-integrity-issue-in-release-routing-via-multiple-public-channels

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 16.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-670
Status published
Products (2)
Capgo/Capgo < 12.128.2
Capgo/Capgo 12.128.2
Published Jun 30, 2026
Tracked Since Jul 01, 2026