Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42q8-ww2w-fgmm

Опубликовано: 10 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.4

Описание

Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs, causing preview misrouting and denial of preview access for victim applications.

Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs, causing preview misrouting and denial of preview access for victim applications.

EPSS

Процентиль: 25%
0.00325
Низкий

5.3 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 6.4
nvd
2 месяца назад

Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dots in preview hostname parsing. Attackers can register app IDs with underscores that collide with other tenants' dotted app IDs, causing preview misrouting and denial of preview access for victim applications.

EPSS

Процентиль: 25%
0.00325
Низкий

5.3 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-436