Known Vulnerabilities for Plugin-auth-backend by @backstage
Listed below are 2 of the newest known vulnerabilities associated with "Plugin-auth-backend" by "@backstage".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-32236 json | Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerab... | Not Provided | 2026-03-12 | 2026-04-15 |
| CVE-2026-4525 json | If a Vault auth mount is configured to pass through the "Authorization" header, and the "Authorization" header is used to aut... | Not Provided | 2026-04-17 | 2026-04-17 |