backend-defaults vulnerabilities
CVEs whose affected-version data names the backend-defaults package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-106494Medium· 4.4Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 0.17.8, the @backstage/backend-defaults package is affected by improper input validation in cloud storage url readers. An attacker with write access to a cloud stora…
▾ Sunlitbackstage · backstagevia NVD
CVE-2026-106492High· 7.6Backstage is an open framework for building developer portals
Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An exter…
▾ Twilightbackstage · backstagevia NVD