CVE-2026-106456

Source
https://cve.org/CVERecord?id=CVE-2026-106456
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106456.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-106456
Aliases
Published
2026-10-06T20:10:41Z
Modified
2026-10-08T02:49:31Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Backstage: Inconsistent credential enforcement for overlapping proxy routes
Details

Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping proxy routes. An operator can configure overlapping proxy paths with different credential requirements. When a parent path permits unauthenticated access and a nested path requires credentials, the parent exemption can also cover requests handled by the nested proxy. An unauthenticated caller may therefore reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy. This issue is fixed in version 0.6.18.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106456.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "0.5.0"
                },
                {
                    "fixed": "0.6.18"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/backstage/backstage

Affected ranges

Type
GIT
Repo
https://github.com/backstage/backstage
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.28.0"
        },
        {
            "fixed": "1.55.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.28.0
v1.29.0
v1.29.0-next.0
v1.29.0-next.1
v1.29.0-next.2
v1.30.0
v1.30.0-next.0
v1.30.0-next.1
v1.30.0-next.2
v1.30.0-next.3
v1.30.0-next.4
v1.31.0
v1.31.0-next.0
v1.31.0-next.1
v1.31.0-next.2
v1.32.0
v1.32.0-next.0
v1.32.0-next.1
v1.32.0-next.2
v1.33.0
v1.33.0-next.0
v1.33.0-next.1
v1.33.0-next.2
v1.33.0-next.3
v1.34.0
v1.34.0-next.0
v1.34.0-next.1
v1.34.0-next.2
v1.35.0
v1.35.0-next.0
v1.35.0-next.1
v1.35.0-next.2
v1.36.0
v1.36.0-next.0
v1.36.0-next.1
v1.36.0-next.2
v1.36.0-next.3
v1.37.0
v1.37.0-next.0
v1.37.0-next.1
v1.37.0-next.2
v1.38.0
v1.38.0-next.0
v1.38.0-next.1
v1.38.0-next.2
v1.39.0
v1.39.0-next.0
v1.39.0-next.1
v1.39.0-next.2
v1.39.0-next.3
v1.40.0
v1.40.0-next.0
v1.40.0-next.1
v1.40.0-next.2
v1.40.0-next.3
v1.41.0
v1.41.0-next.0
v1.41.0-next.1
v1.41.0-next.2
v1.42.0
v1.42.0-next.0
v1.42.0-next.1
v1.42.0-next.2
v1.42.0-next.3
v1.43.0
v1.43.0-next.0
v1.43.0-next.1
v1.43.0-next.2
v1.44.0
v1.44.0-next.0
v1.44.0-next.1
v1.44.0-next.2
v1.44.0-next.3
v1.45.0
v1.45.0-next.0
v1.45.0-next.1
v1.45.0-next.2
v1.45.0-next.3
v1.46.0
v1.46.0-next.0
v1.46.0-next.1
v1.46.0-next.2
v1.47.0
v1.47.0-next.0
v1.47.0-next.1
v1.47.0-next.2
v1.47.0-next.3
v1.48.0
v1.48.0-next.0
v1.48.0-next.1
v1.48.0-next.2
v1.49.0
v1.49.0-next.0
v1.49.0-next.1
v1.49.0-next.2
v1.50.0
v1.50.0-next.0
v1.50.0-next.1
v1.50.0-next.2
v1.51.0
v1.51.0-next.0
v1.51.0-next.1
v1.51.0-next.2
v1.51.0-next.3
v1.52.0
v1.52.0-next.0
v1.52.0-next.1
v1.52.0-next.2
v1.53.0
v1.53.0-next.0
v1.53.0-next.1
v1.53.0-next.2
v1.54.0
v1.54.0-next.0
v1.54.0-next.1
v1.54.0-next.2
v1.54.0-next.3
v1.55.0-next.0
v1.55.0-next.1
v1.55.0-next.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106456.json"