VYPR

@backstage/plugin-catalog-backend-module-gitlab

by Backstage

CVEs (4)

  • CVE-2026-106498HigOct 6, 2026
    risk 0.43cvss 7.7epss —

    Backstage is an open framework for building developer portals. Prior to 3.5.1, 3.6.2, 3.7.2, 3.8.2 and 3.9.1, the @backstage/plugin-catalog-backend package is affected by improper url validation in catalog entity placeholder resolution. An authenticated Backstage user could…

  • CVE-2026-106463MedOct 6, 2026
    risk 0.28cvss 5.4epss —

    Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organizational user ingestion. Deployments that enable GitLab organization event ingestion…

  • CVE-2026-106497MedOct 6, 2026
    risk 0.21cvss 4.3epss —

    Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent catalog property permission evaluation. In deployments that use affected value-based catalog permission conditions as a…

  • CVE-2026-106496LowOct 6, 2026
    risk 0.13cvss 3.1epss —

    Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during catalog processing. Under certain configurations, the catalog backend could…