CVE-2026-56324: Capgo - Rate Limit Bypass via User-Controlled device_id Parameter
Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channelself endpoint that allows attackers to circumvent rate limiting by rotating the user-controlled deviceid parameter. Attackers can send multiple requests per second by changing deviceid values to flood the channeldevices table and cause database exhaustion.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Capgoto a version that resolves this vulnerability.Fixed in 12.128.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-56324?
The severity of CVE-2026-56324 is rated high with a score of 8.8.
How do I fix CVE-2026-56324?
To fix CVE-2026-56324, update Capgo to version 12.128.2 or later.
What type of vulnerability is CVE-2026-56324?
CVE-2026-56324 is a rate limit bypass vulnerability.
What is affected by CVE-2026-56324?
CVE-2026-56324 affects Capgo versions prior to 12.128.2.
How can attackers exploit CVE-2026-56324?
Attackers can exploit CVE-2026-56324 by rotating the user-controlled device_id parameter to bypass rate limits.