---
id: CVE-2026-56228
title: Capgo - Denial of Service via Improper Password Policy Length Validation
summary: >-
  Capgo before 12.128.2 fails to enforce a maximum value on the minimum password
  length field in its password policy configuration. An authenticated
  organization administrator can set an extremely large numeric value (e.g.,
  billions of cha…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'
cvssSource: cna
cwe:
  - CWE-20
vendor: Capgo
product: Capgo
affected:
  - Capgo < 12.128.2
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-23T13:59:40.297209Z'
published: '2026-06-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:30:57.964Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-56228'
references:
  - url: 'https://github.com/Cap-go/capgo/security/advisories/GHSA-vhjp-62qf-33mx'
    label: GHSA Advisory GHSA-vhjp-62qf-33mx
  - url: >-
      https://www.vulncheck.com/advisories/capgo-denial-of-service-via-improper-password-policy-length-validation
    label: >-
      VulnCheck Advisory: Capgo - Denial of Service via Improper Password Policy
      Length Validation
tags:
  - cve.org
epss: 0.00467
epssPercentile: 0.38403
ingestedAt: '2026-10-08T15:49:37.996Z'
---

## Overview

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely large numeric value (e.g., billions of characters) as the minimum password length, making compliance impossible for all organization members. Once the policy is enabled, users (including administrators) are unable to change their passwords or access the organization, resulting in an organization-wide account lockout and application-level denial of service.

## Affected

- `Capgo < 12.128.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
