Weak Parsing Vulnerability in Capgo by Capgo Technologies
CVE-2026-56306
5.3MEDIUM
What is CVE-2026-56306?
The Capgo product, prior to version 12.128.2, is susceptible to a weak parsing vulnerability that occurs in the x-limited-key-id header. This weakness enables attackers to bypass essential subkey enforcement. By submitting malformed inputs, such as zero or duplicate header values, they can generate NaN or falsy outcomes, potentially compromising key scoping. As a result, remote attackers can disable limited key restrictions, allowing them to execute requests under the main API key context instead of operating within the confines of restricted subkey permissions.
Affected Version(s)
Capgo 0 < 12.128.2
Capgo 12.128.2
