---
id: CVE-2026-106456
title: Backstage is an open framework for building developer portals
summary: >-
  Backstage is an open framework for building developer portals. From 0.5.0
  until 0.6.18, the @backstage/plugin-proxy-backend package is affected by
  inconsistent credential enforcement for overlapping proxy routes. An operator
  can configur…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-863
vendor: backstage
product: '@backstage/plugin-proxy-backend'
affected:
  - '@backstage/plugin-proxy-backend >= 0.5.0, < 0.6.18'
patched:
  - '@backstage/plugin-proxy-backend 0.6.18'
published: '2026-10-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:17:32.633'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106456'
references:
  - url: >-
      https://github.com/backstage/backstage/commit/9df92923ac32558bb80edeceafd8de780c44e218
    label: security-advisories@github.com
  - url: 'https://github.com/backstage/backstage/releases/tag/v1.55.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/backstage/backstage/security/advisories/GHSA-472h-9c5j-prrr
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-106456'
  - url: 'https://github.com/advisories/GHSA-472h-9c5j-prrr'
tags:
  - nvd
  - ghsa
  - npm
  - cve.org
aliases:
  - GHSA-472h-9c5j-prrr
ecosystem: npm
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T18:24:26.049704Z'
ingestedAt: '2026-10-06T21:20:28.980Z'
---

## Overview

Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping proxy routes. An operator can configure overlapping proxy paths with different credential requirements. When a parent path permits unauthenticated access and a nested path requires credentials, the parent exemption can also cover requests handled by the nested proxy. An unauthenticated caller may therefore reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy. This issue is fixed in version 0.6.18.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-106456)

Affected packages:

- `@backstage/plugin-proxy-backend >= 0.5.0, < 0.6.18`

Patched in:

- `@backstage/plugin-proxy-backend 0.6.18`

Source: https://github.com/advisories/GHSA-472h-9c5j-prrr
