Vulnerability Description
Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by rotating the user-controlled device_id parameter. Attackers can send multiple requests per second by changing device_id values to flood the channel_devices table and cause database exhaustion.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-77p2-9rcr-5w27
- https://www.vulncheck.com/advisories/capgo-rate-limit-bypass-via-user-controlled
- https://github.com/Cap-go/capgo/security/advisories/GHSA-77p2-9rcr-5w27
FAQ
What is CVE-2026-56324?
CVE-2026-56324 is a vulnerability with a CVSS score of 8.2 (HIGH). Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by rotating the user-controlled device_id parameter. Att...
How severe is CVE-2026-56324?
CVE-2026-56324 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56324?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.