CVE-2026-106557
- EPSS -
- Veröffentlicht 07.10.2026 16:22:53
- Zuletzt bearbeitet 07.10.2026 18:17:16
Backstage is an open framework for building developer portals. Prior to 1.14.6 and 1.15.4, the @backstage/plugin-techdocs-node package did not sufficiently validate TechDocs Markdown extension configuration. An authenticated user who can register or ...
CVE-2026-106563
- EPSS -
- Veröffentlicht 07.10.2026 14:56:08
- Zuletzt bearbeitet 07.10.2026 15:52:18
Backstage is an open framework for building developer portals. Prior to 0.21.8, the @backstage/plugin-kubernetes-backend package is affected by improper entity validation in deprecated kubernetes services endpoint. An authenticated user with Kubernet...
CVE-2026-106562
- EPSS -
- Veröffentlicht 07.10.2026 14:54:13
- Zuletzt bearbeitet 07.10.2026 17:16:51
Backstage is an open framework for building developer portals. Prior to 2.1.6 in @backstage/plugin-search-backend and 1.8.7 in @backstage/plugin-search-backend-module-elasticsearch, search engine permission filtering could return documents denied by ...
- EPSS -
- Veröffentlicht 07.10.2026 14:52:16
- Zuletzt bearbeitet 07.10.2026 17:16:51
Backstage is an open framework for building developer portals. Prior to 0.21.9, the @backstage/plugin-kubernetes-backend package is affected by sensitive information disclosure in kubernetes resource queries. An authenticated user holding the standar...
CVE-2026-106560
- EPSS -
- Veröffentlicht 07.10.2026 14:50:25
- Zuletzt bearbeitet 07.10.2026 18:17:17
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper repository path validation in a scaffolder backend module. An authe...
CVE-2026-106559
- EPSS -
- Veröffentlicht 07.10.2026 14:48:03
- Zuletzt bearbeitet 07.10.2026 17:16:51
Backstage is an open framework for building developer portals. Prior to 0.3.25, the @backstage/plugin-scaffolder-backend-module-confluence-to-markdown package is affected by improper input validation in confluence to markdown scaffolder module. Insuf...
CVE-2026-106558
- EPSS -
- Veröffentlicht 07.10.2026 14:45:25
- Zuletzt bearbeitet 07.10.2026 15:52:18
Backstage is an open framework for building developer portals. Prior to 1.14.8, 1.15.6, and 2.0.1, the @backstage/plugin-techdocs-node package improperly validated mapping-style markdown_extensions configuration. An authenticated attacker who can reg...
CVE-2026-106556
- EPSS -
- Veröffentlicht 07.10.2026 14:39:36
- Zuletzt bearbeitet 07.10.2026 17:16:50
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by configuration bypass in techdocs mkdocs.yml sanitization. Insufficient validation of MkDocs configuration durin...
CVE-2026-106510
- EPSS -
- Veröffentlicht 07.10.2026 14:36:53
- Zuletzt bearbeitet 07.10.2026 18:17:16
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by remote code execution via crafted markdown_extensions in techdocs mkdocs.yml. An authenticated user who can reg...
CVE-2026-106509
- EPSS 0.26%
- Veröffentlicht 06.10.2026 21:50:07
- Zuletzt bearbeitet 07.10.2026 19:17:33
Backstage is an open framework for building developer portals. Prior to 1.14.6, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs theme configuration in techdocs. When TechDocs is configured to build documentati...