Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopback and internal addresses. Organization admins can configure webhooks pointing to localhost or 127.0.0.1, and when triggered, the backend performs outbound requests to these addresses with error responses disclosed to users.
References
Configurations
No configuration.
History
22 Jun 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Cap-go/capgo/security/advisories/GHSA-48hc-53hv-6x3f - |
20 Jun 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-20 16:17
Updated : 2026-06-22 18:36
NVD link : CVE-2026-56227
Mitre link : CVE-2026-56227
CVE.ORG link : CVE-2026-56227
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
