Executive brief
Capgo, a platform for managing app updates and deployments, contains a flaw in how it limits the frequency of incoming requests. An attacker can bypass these protections by spoofing device identifiers, allowing them to flood the system with junk data. This can lead to a denial-of-service (DoS) by exhausting database resources, potentially making the service unavailable for legitimate users.
Technical details
A rate limit bypass exists in the 'channel_self' endpoint of Capgo due to improper resource throttling. The rate limiting logic in 'supabase/functions/_backend/plugins/channel_self.ts' relies on the 'device_id' parameter as a key; however, this parameter is entirely user-controlled and unauthenticated. By rotating 'device_id' values in rapid succession, a remote, unauthenticated attacker can bypass the intended limit of one request per second. Each request triggers a database write via 'upsertChannelDevicePg', which can be exploited to flood the 'channel_devices' table, leading to database exhaustion and a denial-of-service (DoS) condition. The issue is resolved in version 12.128.2.
Affected products
- Capgo Capgo < 12.128.2
Timeline
- 2026-02-10: advisory: Initial GitHub Security Advisory published
- 2026-06-22: disclosed: CVE published to NVD