Information Disclosure Vulnerability in Cap-go from Cap-go
CVE-2026-56316

6.9MEDIUM

Key Information:

Vendor

Cap-go

Status
Vendor
CVE Published:
21 June 2026

What is CVE-2026-56316?

Cap-go versions prior to 12.128.2 feature an information disclosure vulnerability that allows unauthenticated attackers to exploit the OPTIONS /build/upload/:jobId/* endpoint. This flaw permits attackers to enumerate valid builder job IDs based on observable discrepancies in the responses. By probing this endpoint without any form of authentication, an attacker can differentiate between valid and invalid job IDs, enabling them to generate excessive unauthenticated traffic, which can lead to significant resource consumption impacts.

Affected Version(s)

capgo 0 < 12.128.2

capgo 12.128.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Judel777
.