Back

HIGH

Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header

Published Jun 24, 2026

Description

Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope restrictions by referencing their own subkeys, causing all downstream route handlers to use the unrestricted parent key instead of the scoped subkey.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 24, 2026
Updated Jun 24, 2026
Reserved Jun 19, 2026
CISA Vulnrichment
Updated Jun 24, 2026
NVD
Status Deferred
Modified Jun 25, 2026
Red Hat
Severity n/a
Public date n/a