Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q333-f498-w2x7 | Backstage: Insufficient audience validation in the Cloudflare Access auth provider |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 07 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audience validation in the cloudflare access auth provider. The Cloudflare Access auth provider verifies a token's signature and team issuer, but affected versions do not verify that the token was issued for the Backstage application. A user holding a valid token for another Access application in the same Cloudflare Zero Trust team may therefore be able to authenticate to Backstage if that token reaches the auth endpoint without the Backstage application's audience already being enforced upstream. Cloudflare Access normally evaluates the protected application before forwarding requests. This issue is fixed in version 0.5.0. | |
| Title | Backstage: Insufficient audience validation in the Cloudflare Access auth provider | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T15:09:19.708Z
Reserved: 2026-10-06T16:49:40.591Z
Link: CVE-2026-106457
Updated: 2026-10-07T15:06:29.348Z
Status : Awaiting Analysis
Published: 2026-10-06T21:17:16.083
Modified: 2026-10-07T16:17:38.710
Link: CVE-2026-106457
No data.
OpenCVE Enrichment
Updated: 2026-10-07T00:30:08Z
Github GHSA