CVE-2026-106496: Backstage: Inconsistent enforcement of allowed location types during catalog processing
Under certain configurations, the catalog backend could process location types that were not intended to be allowed, potentially leading to unintended file access on the backend host.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-106496 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →