CVE-2026-56329: Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding
Published Jul 10, 2026
·Updated
Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs, causing preview misrouting and denial of preview access for victim applications.
Affected Software
1 affected component
Capgo Capgo<12.128.2
Event History
Jul 10, 2026
CVE Published
via MITRE·01:57 PM
Data Sourced
via MITRE·01:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-56329?
The severity of CVE-2026-56329 is rated medium with a score of 5.3.
2
What type of vulnerability is CVE-2026-56329?
CVE-2026-56329 is a cross-tenant preview namespace collision vulnerability.
3
How does CVE-2026-56329 affect users of Capgo?
CVE-2026-56329 can allow attackers to register app IDs that collide with other tenants, leading to preview misrouting.
4
What versions of Capgo are affected by CVE-2026-56329?
CVE-2026-56329 affects Capgo versions prior to 12.128.2.
5
How do I fix CVE-2026-56329?
To fix CVE-2026-56329, upgrade to Capgo version 12.128.2 or later.