Vulnerability Description
Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly resolve to a single hidden winner channel. An authorized app or channel manager can create ambiguous default update state and silently influence which bundle unnamed clients receive, breaking release routing integrity and predictability.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/Cap-go/capgo/security/advisories/GHSA-3cmp-pm5x-8464
- https://www.vulncheck.com/advisories/capgo-integrity-issue-in-release-routing-vi
- https://github.com/Cap-go/capgo/security/advisories/GHSA-3cmp-pm5x-8464
FAQ
What is CVE-2026-56328?
CVE-2026-56328 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly resolve to a single hid...
How severe is CVE-2026-56328?
CVE-2026-56328 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56328?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.