Backstage
Backstage Plugin Techdocs Backend: vulnerabilities and CVEs
Backstage Plugin Techdocs Backend has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs2
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-106490 | Medium (6.5) | — | — | Oct 6, 2026 | Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper input validation in techdocs static content requests. When using the… |
| CVE-2026-106489 | Medium (6.5) | — | — | Oct 6, 2026 | Backstage is an open framework for building developer portals. Prior to 2.2.4, the @backstage/plugin-techdocs-backend package is affected by improper authorization enforcement for techdocs static content. An… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by Backstage
Plugin-scaffolder-backend · 5Plugin Scaffolder Backend · 5Plugin Techdocs Node · 5Plugin Catalog Backend · 3Backend Defaults · 2Plugin-scaffolder-node · 2Plugin-auth-backend · 1Plugin-app-backend · 1Plugin-proxy-backend · 1Plugin-auth-node · 1Permissions · 1Plugin-auth-backend-module-oidc-provider · 1