Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @backstage/plugin-kubernetes-backend
  4. ›
  5. CVE-2026-106561

CVE-2026-106561: Backstage has a sensitive information disclosure in Kubernetes resource queries

October 7, 2026

An authenticated user holding the standard Kubernetes resource read permission could retrieve sensitive values that the Kubernetes plugin is designed to mask, potentially exposing credentials and other confidential material held in the connected clusters. Exposure is limited to resources that the Backstage service account is permitted to read and that match the targeted catalog entity’s namespace and label selector. Deployments whose cluster credentials do not grant read access to these resources are unaffected.

References

  • github.com/advisories/GHSA-p795-mqf2-36mf
  • github.com/backstage/backstage/commit/388926ae5734bc20bd6a1520d02896be834f6527
  • github.com/backstage/backstage/releases/tag/v1.54.2
  • github.com/backstage/backstage/security/advisories/GHSA-p795-mqf2-36mf
  • nvd.nist.gov/vuln/detail/CVE-2026-106561

Code Behaviors & Features

Detect and mitigate CVE-2026-106561 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.21.9

Fixed versions

  • 0.21.9

Solution

Upgrade to version 0.21.9 or above.

Impact 5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
  • CWE-863: Incorrect Authorization

Source file

npm/@backstage/plugin-kubernetes-backend/CVE-2026-106561.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sun, 11 Oct 2026 00:18:44 +0000.