Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q2x5-4xjx-c6p9 | Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow` |
Sat, 25 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation backstage\/backend Defaults
|
|
| CPEs | cpe:2.3:a:linuxfoundation:backstage\/backend_defaults:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Linuxfoundation \@backstage\/backend Defaults
|
Linuxfoundation backstage\/backend Defaults
|
Thu, 09 Apr 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation \@backstage\/backend Defaults |
|
| CPEs | cpe:2.3:a:linuxfoundation:\@backstage\/backend_defaults:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
Linuxfoundation
Linuxfoundation \@backstage\/backend Defaults |
Tue, 27 Jan 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Backstage
Backstage backstage |
|
| Vendors & Products |
Backstage
Backstage backstage |
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals, and @backstage/backend-defaults provides the default implementations and setup for a standard Backstage backend app. Prior to versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0, the `FetchUrlReader` component, used by the catalog and other plugins to fetch content from URLs, followed HTTP redirects automatically. This allowed an attacker who controls a host listed in `backend.reading.allow` to redirect requests to internal or sensitive URLs that are not on the allowlist, bypassing the URL allowlist security control. This is a Server-Side Request Forgery (SSRF) vulnerability that could allow access to internal resources, but it does not allow attackers to include additional request headers. This vulnerability is fixed in `@backstage/backend-defaults` version 0.12.2, 0.13.2, 0.14.1, and 0.15.0. Users should upgrade to this version or later. Some workarounds are available. Restrict `backend.reading.allow` to only trusted hosts that you control and that do not issue redirects, ensure allowed hosts do not have open redirect vulnerabilities, and/or use network-level controls to block access from Backstage to sensitive internal endpoints. | |
| Title | Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow` | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-22T16:48:55.954Z
Reserved: 2026-01-20T22:30:11.778Z
Link: CVE-2026-24048
Updated: 2026-01-22T15:09:14.747Z
Status : Analyzed
Published: 2026-01-21T23:15:53.580
Modified: 2026-04-25T18:01:55.150
Link: CVE-2026-24048
OpenCVE Enrichment
Updated: 2026-04-18T15:45:04Z
Github GHSA