Impact
Capgo before version 12.128.2 allows attackers to register application identifiers that include double underscores, which the system non‑bijectively decodes into dots when parsing preview hostnames. This misinterpretation creates a namespace collision whereby a tenant’s preview request is routed to another tenant’s application, resulting in unintended denial of preview access for the victim. This issue is a CWE-436.
Affected Systems
Capgo, all deployments running any version older than 12.128.2 are affected. The vulnerability is present in the preview hostname parsing logic used by all tenants that register application identifiers containing double underscores.
Risk and Exploitability
The CVSS score of 5.3 classifies this issue as medium severity. The EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed large‑scale exploitation so far. To exploit it, an attacker must be able to register a new application identifier containing double underscores or otherwise control the registration. Successful exploitation results in denial of preview service for the affected tenant but does not provide direct information disclosure or remote code execution. Given the medium severity and the requirement for tenant‑level access to create the colliding identifier, the overall risk remains moderate.
OpenCVE Enrichment