GHSA-r9ph-3637-55px

Suggest an improvement
Source
https://github.com/advisories/GHSA-r9ph-3637-55px
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-r9ph-3637-55px/GHSA-r9ph-3637-55px.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r9ph-3637-55px
Aliases
  • CVE-2026-106563
Published
2026-10-07T18:02:37Z
Modified
2026-10-07T18:15:11Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Backstage: Improper entity validation in deprecated Kubernetes services endpoint
Details

Impact

An authenticated user with Kubernetes read permissions could access Kubernetes workload data beyond their intended scope by supplying crafted entity data to the deprecated services endpoint. The exposure is limited to read-only access to Kubernetes object metadata across configured clusters.

Patches

Patched in @backstage/plugin-kubernetes-backend version 0.21.8.

Workarounds

  • Disable the deprecated /services/:serviceId route by deploying a custom Kubernetes router that omits it.
  • Restrict access to the kubernetes.resources.read permission to limit the set of users who can reach the endpoint.
Database specific
{
    "cwe_ids": [
        "CWE-20",
        "CWE-862"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-07T18:02:37Z",
    "nvd_published_at": "2026-10-07T15:17:17Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / @backstage/plugin-kubernetes-backend

Package

Name
@backstage/plugin-kubernetes-backend
View open source insights on deps.dev
Purl
pkg:npm/%40backstage/plugin-kubernetes-backend

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.21.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-r9ph-3637-55px/GHSA-r9ph-3637-55px.json"