Broken Cursor Pagination in Cap-go Affects Cloudflare Product
CVE-2026-56307
5.3MEDIUM
What is CVE-2026-56307?
A critical vulnerability exists in Cap-go versions prior to 12.128.12 that allows authenticated attackers with app.read_devices access to exploit the /private/devices endpoint. This vulnerability leads to broken cursor pagination, which can result in infinite pagination loops, preventing users from navigating datasets efficiently. Consequently, attackers can disrupt device management workflows by causing repeated processing, making certain rows unreachable and hindering overall data accessibility.
Affected Version(s)
capgo 0 < 12.128.12
capgo 12.128.12
