CVE-2026-32235: Linuxfoundation Backstage
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured allowedRedirectUriPatterns are affected. A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token. This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default. This vulnerability is fixed in 0.27.1.
Affected products
- Linuxfoundation Backstage: up to and including 0.27.0
Published 2026-03-12. Last modified 2026-06-17.