Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-56227

Опубликовано: 20 июн. 2026
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.

EPSS

Процентиль: 18%
0.0026
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.4
github
около 2 месяцев назад

Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.

EPSS

Процентиль: 18%
0.0026
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-918