CVE-2026-56329: Capgo
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs, causing preview misrouting and denial of preview access for victim applications.
Affected products
- Capgo Capgo: before 12.128.2 (fixed in 12.128.2)
Published 2026-07-10. Last modified 2026-07-10.