Capgo – Subkey Scope Bypass in middlewareKey via x-limited-key-id Header_CVE-2026-56232
Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareKey function. Attackers can bypass subkey scope restrictions by referencing their own subkeys, causing all downstream route handl...