Broken Cursor Pagination in Cap-go Affects Cloudflare Product
CVE-2026-56307

5.3MEDIUM

Key Information:

Vendor

Cap-go

Status
Vendor
CVE Published:
20 June 2026

What is CVE-2026-56307?

A critical vulnerability exists in Cap-go versions prior to 12.128.12 that allows authenticated attackers with app.read_devices access to exploit the /private/devices endpoint. This vulnerability leads to broken cursor pagination, which can result in infinite pagination loops, preventing users from navigating datasets efficiently. Consequently, attackers can disrupt device management workflows by causing repeated processing, making certain rows unreachable and hindering overall data accessibility.

Affected Version(s)

capgo 0 < 12.128.12

capgo 12.128.12

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.