CVE-2026-32236

medium Red Hat
CVSS v3 Base Score
0.0
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N
Published: March 12, 2026
Last Modified: March 12, 2026
Vendor: Red Hat
Source: REDHAT

Description

A server side request forgery flaw has been discovered in the npm @backstage/plugin-auth-backend package. The CIMD metadata fetch validates the initial client_id hostname against private IP ranges but does not apply the same validation after HTTP redirects. The practical impact is limited. The attacker cannot read the response body from the internal request, cannot control request headers or method, and the feature must be explicitly enabled via an experimental flag that is off by default. Deployments that restrict allowedClientIdPatterns to specific trusted domains are not affected.

CWE

CWE-918

Affected Products

Red Hat Developer HubSelf-service automation portal 2

References