CVE-2026-56338

MEDIUM

Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint

Title source: cna
STIX 2.1

Description

Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authentication due to captcha validation failures. Authenticated users cannot complete 2FA enrollment as the backend consistently returns HTTP 500 errors with captcha verification process failed messages, blocking access to security controls.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-m53g-7gcj-x6f7)
https://github.com/Cap-go/capgo/security/advisories/GHSA-m53g-7gcj-x6f7
Third Party Advisory third-party-advisory
VulnCheck Advisory: Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint
https://www.vulncheck.com/advisories/capgo-denial-of-service-in-2fa-email-verification-via-auth-v1-otp-endpoint

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 20.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-703
Status published
Products (2)
Capgo/Capgo < 12.128.2
Capgo/Capgo 12.128.2
Published Jun 24, 2026
Tracked Since Jun 24, 2026