Security Advisory

CVE-2026-56306

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-22 21:04:46
Last updated 2026-06-23 12:11:26
Assigner VulnCheck
CVSS score 5.3
State PUBLISHED

Description

Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypass subkey enforcement by submitting malformed values, zero, or duplicate headers that result in NaN or falsy values. Remote attackers can manipulate the x-limited-key-id header to disable limited key scoping and execute requests using the main API key context instead of restricted subkey permissions.