PT-2026-51152 · Cap Go · Cap-Go
Judel777
·
Published
2026-06-20
·
Updated
2026-06-20
·
CVE-2026-56282
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Capgo versions prior to 12.128.2
Description
An information disclosure issue exists in the unauthenticated '/replication' endpoint. This allows attackers to retrieve internal PostgreSQL replication telemetry without authentication, exposing sensitive infrastructure details such as replication slot names,
confirmed flush lsn, restart lsn values, and database error messages for reconnaissance purposes.Recommendations
Update to version 12.128.2 or later.
As a temporary workaround, restrict access to the '/replication' endpoint to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cap-Go