← volver
CVE-2026-56307

Cap-go - Broken Cursor Pagination in /private/devices Endpoint

CVSS 5.3 MEDIUMEPSS 0.2%CWE-670
Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page loops and make later rows unreachable. Attackers with app.read_devices access can exploit non-advancing cursor filters to trigger infinite pagination loops, prevent dataset traversal, and cause repeated processing in device-management workflows.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Productos afectados
Cap-go · capgo

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →