Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

backstage — Vulnerabilities & Security Advisories 67

Browse all 67 CVE security advisories affecting backstage. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Backstage is an open-source developer portal platform designed to unify internal developer tools and services under a single interface. Its architecture facilitates service cataloging, documentation, and tool integration, making it a central hub for engineering teams. Security assessments have identified twenty-four Common Vulnerabilities and Exposures (CVEs), primarily stemming from its complex plugin ecosystem and API gateways. Historically, the most prevalent vulnerability classes include Cross-Site Scripting (XSS) and improper access control mechanisms, which often lead to privilege escalation or unauthorized data exposure. While no single catastrophic incident has defined its history, the accumulation of these flaws highlights risks associated with third-party plugin dependencies and insufficient input validation. Organizations deploying this solution must prioritize rigorous plugin auditing and strict role-based access controls to mitigate the inherent risks of its extensible framework.

Top products by backstage: backstage
CVE ID Title CVSS Severity Published
CVE-2026-106557 Backstage: Improper input validation in TechDocs Markdown extension configuration — backstage CWE-22 7.7 High 2026-10-07
CVE-2026-106563 Backstage: Improper entity validation in deprecated Kubernetes services endpoint — backstage CWE-20 5.3 Medium 2026-10-07
CVE-2026-106562 Backstage: Incorrect authorization in search engine permission filtering — backstage CWE-754 4.3 Medium 2026-10-07
CVE-2026-106561 Backstage: Sensitive information disclosure in Kubernetes resource queries — backstage CWE-200 5.0 Medium 2026-10-07
CVE-2026-106560 Backstage: Improper repository path validation in a Scaffolder backend module — backstage CWE-22 7.1 High 2026-10-07
CVE-2026-106559 Backstage: Improper input validation in Confluence to Markdown scaffolder module — backstage CWE-22 6.3 Medium 2026-10-07
CVE-2026-106558 Backstage: Improper validation of TechDocs MkDocs configuration — backstage CWE-502 8.8 High 2026-10-07
CVE-2026-106556 Backstage: Configuration bypass in TechDocs mkdocs.yml sanitization — backstage CWE-78 7.7 High 2026-10-07
CVE-2026-106510 Backstage: Remote code execution via crafted markdown_extensions in TechDocs mkdocs.yml — backstage CWE-183 7.7 High 2026-10-07
CVE-2026-106509 Backstage: Improper validation of MkDocs theme configuration in TechDocs — backstage CWE-94 7.7 High 2026-10-06
CVE-2026-106508 Backstage: Potential file exposure through local TechDocs publisher — backstage CWE-22 5.3 Medium 2026-10-06
CVE-2026-106507 Backstage: TechDocs arbitrary file read via mkdocs snippets — backstage CWE-59 5.3 Medium 2026-10-06
CVE-2026-106506 Backstage: Improper input validation in scaffolder task list ordering — backstage CWE-202 5.3 Medium 2026-10-06
CVE-2026-106505 Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend — backstage CWE-426 7.7 High 2026-10-06
CVE-2026-106504 Backstage: Sensitive information exposure in scaffolder task logs — backstage CWE-532 6.5 Medium 2026-10-06
CVE-2026-106503 Backstage: Scaffolder action input authorization bypass — backstage CWE-178 8.1 High 2026-10-06
CVE-2026-106502 Backstage: Sensitive information may be exposed in Scaffolder task failure events — backstage CWE-532 5.3 Medium 2026-10-06
CVE-2026-106501 Backstage: Sensitive information exposure in Scaffolder — backstage CWE-200 9.6 Critical 2026-10-06
CVE-2026-106500 Backstage: Improper task state validation in Scaffolder backend — backstage CWE-59 8.5 High 2026-10-06
CVE-2026-106499 Backstage: Secret-derived values may be exposed in scaffolder task logs — backstage CWE-532 4.9 Medium 2026-10-06
CVE-2026-106498 Backstage: Improper URL validation in catalog entity placeholder resolution — backstage CWE-863 7.7 High 2026-10-06
CVE-2026-106497 Backstage: Inconsistent catalog property permission evaluation — backstage CWE-178 4.3 Medium 2026-10-06
CVE-2026-106496 Backstage: Inconsistent enforcement of allowed location types during catalog processing — backstage CWE-22 3.1 Low 2026-10-06
CVE-2026-106494 Backstage: Improper input validation in cloud storage URL readers — backstage CWE-22 4.4 Medium 2026-10-06
CVE-2026-106493 Backstage: Cloud storage catalog locations may cross configured storage boundaries — backstage CWE-22 3.0 Low 2026-10-06
CVE-2026-106492 Backstage: Improper preservation of access restrictions during service credential delegation — backstage CWE-269 7.6 High 2026-10-06
CVE-2026-106491 Backstage: Improper input validation in proxy-backend — backstage CWE-20 6.4 Medium 2026-10-06
CVE-2026-106490 Backstage: Improper input validation in TechDocs static content requests — backstage CWE-22 6.5 Medium 2026-10-06
CVE-2026-106489 Backstage: Improper authorization enforcement for TechDocs static content — backstage CWE-22 6.5 Medium 2026-10-06
CVE-2026-106488 Backstage: Improper authentication in the OIDC provider — backstage CWE-287 8.1 High 2026-10-06

This page lists every published CVE security advisory associated with backstage. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.