CVE-2026-106456: Backstage: Inconsistent credential enforcement for overlapping proxy routes
Impact
An operator can configure overlapping proxy paths with different credential requirements. When a parent path permits unauthenticated access and a nested path requires credentials, the parent exemption can also cover requests handled by the nested proxy. An unauthenticated caller may therefore reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy.
Exploitation requires this specific overlapping route configuration. The resulting confidentiality and integrity impact depends on the capabilities exposed by the nested upstream.
Patches
Upgrade @backstage/plugin-proxy-backend to version 0.6.18 or later. The fixed package is available in Backstage v1.55.0.
Workarounds
- Avoid nesting a credential-protected proxy path below a path configured with dangerously-allow-unauthenticated. - Apply the same credential requirement to overlapping proxy paths. - Restrict direct network access to the Backstage backend until the patched package is deployed.
Other sources
Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping proxy routes. An operator can configure overlapping proxy paths with different credential requirements. When a parent path permits unauthenticated access and a nested path requires credentials, the parent exemption can also cover requests handled by the nested proxy. An unauthenticated caller may therefore reach the nested upstream through Backstage, including with static upstream credentials configured for that proxy. This issue is fixed in version 0.6.18.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@backstage/plugin-proxy-backendto a version that resolves this vulnerability.Fixed in 0.6.18 - Upgrade
Upgrade
@backstage/plugin-proxy-backendto a version that resolves this vulnerability.Fixed in 0.6.18 - Configuration
Apply the same credential requirement to overlapping proxy paths, and do not nest a credential-protected proxy path below a path configured with dangerously-allow-unauthenticated.
Backstage proxy routes credential requirements for overlapping proxy paths = same credential requirement - Compensating control
Restrict direct network access to the Backstage backend until the patched package is deployed.
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated access?
Deployments are exposed only when they configure overlapping proxy paths such that a parent path allows unauthenticated access while a nested path requires credentials. Requests handled by the nested proxy can then inherit the parent path's exemption.
What could an unauthenticated attacker access?
An unauthenticated caller may reach the nested upstream service through Backstage. This can include access using static upstream credentials configured for the nested proxy.
Are default proxy configurations affected?
The issue depends on an operator-created overlapping route configuration with conflicting credential requirements. The provided information does not indicate that a default configuration creates this condition.
What versions should be remediated?
The affected range is from 0.5.0 until 0.6.18 of @backstage/plugin-proxy-backend, and the issue is fixed in version 0.6.18. If immediate upgrading is not possible, remove or avoid overlapping parent and nested proxy paths where the parent permits unauthenticated access and the nested route requires credentials.
How can an operator determine whether their configuration is at risk?
Review proxy route definitions for nested or overlapping paths. A configuration is at risk if an unauthenticated parent route overlaps a child route intended to require credentials.