Catalog entity providers for Azure Blob Storage and AWS S3 did not sufficiently validate storage object paths, which could allow catalog descriptors to be read from outside the intended storage boundary. Access is limited to locations reachable by the backend's configured credentials.
@backstage/plugin-catalog-backend-module-azure version 0.3.21@backstage/plugin-catalog-backend-module-aws version 0.4.27@backstage/backend-defaults version 0.7.18{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-07T17:59:55Z",
"nvd_published_at": "2026-10-06T21:17:18Z",
"severity": "LOW"
}