Backstage
Backstage Plugin-proxy-backend: vulnerabilities and CVEs
Backstage Plugin-proxy-backend has 1 published vulnerabilities, 1 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs1
Last 12 months1
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-106456 | Medium (4.8) | — | — | Oct 6, 2026 | Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping proxy routes. An… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Backstage
Plugin-scaffolder-backend · 5Plugin Scaffolder Backend · 5Plugin Techdocs Node · 5Plugin Catalog Backend · 3Backend Defaults · 2Plugin-scaffolder-node · 2Plugin Techdocs Backend · 2Plugin-auth-backend · 1Plugin-app-backend · 1Plugin-auth-node · 1Permissions · 1Plugin-auth-backend-module-oidc-provider · 1