HIGH
Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header
Published Jun 24, 2026
8.7
HIGHCVSS 4.0
EPSS 0.47%
Description
Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope restrictions by referencing their own subkeys, causing all downstream route handlers to use the unrestricted parent key instead of the scoped subkey.
Affected products
-
- Version 0StatusaffectedConstraints<12.128.2
- Version 12.128.2StatusunaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/Cap-go/capgo/security/advisories/GHSA-2h89-vcvx-5pvh exploitvendor-advisory
- https://www.vulncheck.com/advisories/capgo-subkey-scope-bypass-in-middlewarekey-via-x-limited-key-id-header third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/Cap-go/capgo/security/advisories/GHSA-2h89-vcvx-5pvh | exploitvendor-advisory | |
| https://www.vulncheck.com/advisories/capgo-subkey-scope-bypass-in-middlewarekey-via-x-limited-key-id-header | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 24, 2026
Updated Jun 24, 2026
Reserved Jun 19, 2026
Link CVE-2026-56232
CISA Vulnrichment
Updated Jun 24, 2026