CVE-2026-106498: Backstage: Improper URL validation in catalog entity placeholder resolution
An authenticated Backstage user could craft a catalog entity with placeholder directives that reference resources outside the entity’s source repository. Under certain configurations, this could allow access to data not intended to be available to the user.
References
- github.com/advisories/GHSA-qgvj-qcf8-xq73
- github.com/backstage/backstage/commit/0b0f6fc89b4eb4872c76a498abbe1dc65998bb6e
- github.com/backstage/backstage/commit/286bfc1f9cc3608a073b41016be302785be385d1
- github.com/backstage/backstage/commit/61a10f19926aeda7f4a32de48d733e6710584634
- github.com/backstage/backstage/commit/99729e925fd2bd40ba210022351a0ee6318e6197
- github.com/backstage/backstage/commit/e786ac309ed2d775daf2309393c015c43902d6f6
- github.com/backstage/backstage/releases/tag/v1.49.6
- github.com/backstage/backstage/releases/tag/v1.50.5
- github.com/backstage/backstage/releases/tag/v1.51.3
- github.com/backstage/backstage/releases/tag/v1.53.2
- github.com/backstage/backstage/releases/tag/v1.54.6
- github.com/backstage/backstage/security/advisories/GHSA-qgvj-qcf8-xq73
- nvd.nist.gov/vuln/detail/CVE-2026-106498
Code Behaviors & Features
Detect and mitigate CVE-2026-106498 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →