VYPR

@backstage/plugin-proxy-backend

by Backstage

CVEs (2)

  • CVE-2026-106491MedOct 6, 2026
    risk 0.35cvss 6.4epss —

    Backstage is an open framework for building developer portals. Prior to 0.6.17, the @backstage/plugin-proxy-backend package is affected by improper input validation in proxy-backend. An authenticated Backstage user could craft a request URL that causes the proxy-backend to…

  • CVE-2026-106456MedOct 6, 2026
    risk 0.24cvss 4.8epss —

    Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping proxy routes. An operator can configure overlapping proxy paths with different…