Information Disclosure Vulnerability in Cap-go from Cap-go
CVE-2026-56316
6.9MEDIUM
What is CVE-2026-56316?
Cap-go versions prior to 12.128.2 feature an information disclosure vulnerability that allows unauthenticated attackers to exploit the OPTIONS /build/upload/:jobId/* endpoint. This flaw permits attackers to enumerate valid builder job IDs based on observable discrepancies in the responses. By probing this endpoint without any form of authentication, an attacker can differentiate between valid and invalid job IDs, enabling them to generate excessive unauthenticated traffic, which can lead to significant resource consumption impacts.
Affected Version(s)
capgo 0 < 12.128.2
capgo 12.128.2
