CVE-2026-106493: Backstage: Cloud storage catalog locations may cross configured storage boundaries
Catalog entity providers for Azure Blob Storage and AWS S3 did not sufficiently validate storage object paths, which could allow catalog descriptors to be read from outside the intended storage boundary. Access is limited to locations reachable by the backend’s configured credentials.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-106493 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →