CVE-2026-56248: Uncontrolled Resource Consumption in Cap-go capgo
Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries to the public.audit_logs endpoint using the public anon key consistently trigger statement timeouts (PostgREST error 57014). Under concurrency, this exhausts database resources and causes cascading HTTP 500 failures on unrelated endpoints (e.g. /orgs), resulting in an application-layer denial of service.
AI Analysis
Technical Summary
CVE-2026-56248 describes an unauthenticated denial-of-service vulnerability in Cap-go capgo-backend versions prior to 12.128.12. The issue arises from the audit_logs table's Row-Level Security (RLS) policy when accessed through the Supabase PostgREST API. The PostgreSQL query planner performs costly query planning before applying RLS filters, allowing unfiltered queries to the public.audit_logs endpoint using the public anon key to consistently cause statement timeouts (error 57014). When multiple such queries occur concurrently, database resources become exhausted, causing cascading HTTP 500 errors on unrelated endpoints such as /orgs, effectively causing an application-layer denial of service.
Potential Impact
An attacker can trigger unauthenticated denial of service by sending unfiltered queries to the public.audit_logs endpoint via the public anon key. This causes PostgreSQL statement timeouts and resource exhaustion under concurrency, leading to cascading failures and HTTP 500 errors on unrelated application endpoints. This disrupts normal application availability and functionality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation is currently documented. Until a fix is available, restricting access to the public.audit_logs endpoint or disabling the public anon key for this endpoint may reduce exposure.
CVE-2026-56248: Uncontrolled Resource Consumption in Cap-go capgo
Description
Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries to the public.audit_logs endpoint using the public anon key consistently trigger statement timeouts (PostgREST error 57014). Under concurrency, this exhausts database resources and causes cascading HTTP 500 failures on unrelated endpoints (e.g. /orgs), resulting in an application-layer denial of service.
CVSS v4.0
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-56248 describes an unauthenticated denial-of-service vulnerability in Cap-go capgo-backend versions prior to 12.128.12. The issue arises from the audit_logs table's Row-Level Security (RLS) policy when accessed through the Supabase PostgREST API. The PostgreSQL query planner performs costly query planning before applying RLS filters, allowing unfiltered queries to the public.audit_logs endpoint using the public anon key to consistently cause statement timeouts (error 57014). When multiple such queries occur concurrently, database resources become exhausted, causing cascading HTTP 500 errors on unrelated endpoints such as /orgs, effectively causing an application-layer denial of service.
Potential Impact
An attacker can trigger unauthenticated denial of service by sending unfiltered queries to the public.audit_logs endpoint via the public anon key. This causes PostgreSQL statement timeouts and resource exhaustion under concurrency, leading to cascading failures and HTTP 500 errors on unrelated application endpoints. This disrupts normal application availability and functionality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary mitigation is currently documented. Until a fix is available, restricting access to the public.audit_logs endpoint or disabling the public anon key for this endpoint may reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-06-19T21:53:16.001Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a3a81fdeed863c81e009c53
Added to database: 06/23/2026, 12:54:21 UTC
Last enriched: 06/23/2026, 13:09:06 UTC
Last updated: 08/05/2026, 12:41:16 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.