GHSA-9ghw-48h5-v2w5MediumCVSS 6.4
Backstage: Improper input validation in proxy-backend
🔗 CVE IDs covered (1)
📋 Description
Impact
An authenticated Backstage user could craft a request URL that causes the proxy-backend to forward the request to a path outside the configured base path on the target server. This is limited to target servers already configured as proxy endpoints and requires Backstage authentication by default.
Patches
Patched in @backstage/plugin-proxy-backend version 0.6.17
Workarounds
- Deploy a reverse proxy or WAF in front of Backstage that normalizes request paths before they reach the backend.
🎯 Affected products1
- npm/@backstage/plugin-proxy-backend:< 0.6.17
🔗 References (5)
- https://github.com/backstage/backstage/security/advisories/GHSA-9ghw-48h5-v2w5
- https://nvd.nist.gov/vuln/detail/CVE-2026-106491
- https://github.com/backstage/backstage/commit/233287d0ce3133e41549bf92a7470c940a41753c
- https://github.com/backstage/backstage/releases/tag/v1.54.6
- https://github.com/advisories/GHSA-9ghw-48h5-v2w5