Metrics
Affected Vendors & Products
Wed, 24 Jun 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cap-go
Cap-go cap-go |
|
| Vendors & Products |
Cap-go
Cap-go cap-go |
Mon, 22 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 20 Jun 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users. | |
| Title | Capgo - Server-Side Request Forgery via Webhook URL Validation | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-22T12:45:02.541Z
Reserved: 2026-06-19T21:46:58.630Z
Link: CVE-2026-56227
Updated: 2026-06-22T12:44:44.789Z
Status : Deferred
Published: 2026-06-20T16:17:04.417
Modified: 2026-06-22T18:36:28.807
Link: CVE-2026-56227
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:15:07Z