GHSA-826h-28h9-65hg

Suggest an improvement
Source
https://github.com/advisories/GHSA-826h-28h9-65hg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-826h-28h9-65hg/GHSA-826h-28h9-65hg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-826h-28h9-65hg
Aliases
Published
2026-10-07T18:01:02Z
Modified
2026-10-07T18:15:10Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Backstage: Improper authentication in the OIDC provider
Details

Impact

Deployments using OIDC email-based identity resolution with a provider that permits unverified email addresses may allow an authenticated provider user to assume another catalog identity. This may grant access and permissions associated with that user. No direct availability impact is demonstrated.

Patches

Patched in @backstage/plugin-auth-backend-module-oidc-provider version 0.4.20.

Workarounds

  • Disable email-based sign-in resolution for the OIDC provider, or require the identity provider to verify email addresses before allowing sign-in.
Database specific
{
    "cwe_ids": [
        "CWE-287"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T18:01:02Z",
    "nvd_published_at": "2026-10-06T21:17:17Z",
    "severity": "HIGH"
}
References

Affected packages

npm / @backstage/plugin-auth-backend-module-oidc-provider

Package

Name
@backstage/plugin-auth-backend-module-oidc-provider
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-auth-backend-module-oidc-provider

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.20

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-826h-28h9-65hg/GHSA-826h-28h9-65hg.json"