Junglewise Threat Intelligence

CVE-2026-56307: Cap-go broken cursor pagination in /private/devices endpoint

CVE-2026-56307 · Severity: medium · CVSS 4.3 · Published 2026-06-20

Technologies: Cap-go. Vendors: Cap-go.

Executive brief

Cap-go, a tool for managing app updates and devices, contains a flaw in how it handles lists of devices on its Cloudflare-hosted infrastructure. An authorized user can trigger a loop that prevents them from seeing all registered devices, instead receiving the same data repeatedly. This can disrupt administrative workflows, cause automated management tools to hang or crash, and prevent the export of complete device datasets.

Technical details

A broken cursor pagination vulnerability exists in the /private/devices endpoint of Cap-go when running on the Cloudflare/workerd path. The root cause is an incorrect implementation of the cursor filter in `readDevicesCF()`, where the `nextCursor` fails to advance correctly during dataset traversal. An authenticated attacker with `app.read_devices` permissions can exploit this by replaying the returned cursor, which results in duplicate pages and `hasMore=true` remaining set indefinitely. This leads to a denial-of-service condition for device management workflows, as later rows in the dataset become unreachable and client-side iteration may loop infinitely. The issue was fixed in version 12.128.12.

Affected products

  • Cap-go capgo < 12.128.12

Timeline

  • 2026-05-08: advisory: Vendor advisory published on GitHub
  • 2026-06-20: disclosed: CVE published to NVD

References