CVE-2026-56314

Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing app_versions.deleted filter in channel version joins.
Configurations

No configuration.

History

23 Jun 2026, 15:16

Type Values Removed Values Added
References () https://github.com/Cap-go/capgo/security/advisories/GHSA-hqq2-87cp-j83x - () https://github.com/Cap-go/capgo/security/advisories/GHSA-hqq2-87cp-j83x -

22 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 22:16

Updated : 2026-06-23 15:16


NVD link : CVE-2026-56314

Mitre link : CVE-2026-56314

CVE.ORG link : CVE-2026-56314


JSON object : View

Products Affected

No product.

CWE
CWE-672

Operation on a Resource after Expiration or Release