Catalog entity providers for Azure Blob Storage and AWS S3 did not sufficiently validate storage object paths, which could allow catalog descriptors to be read from outside the intended storage boundary. Access is limited to locations reachable by the backend's configured credentials.
// patches
@backstage/plugin-catalog-backend-module-azure version 0.3.21
@backstage/plugin-catalog-backend-module-aws version 0.4.27
@backstage/backend-defaults version 0.7.18
// workarounds
Restrict blob and object creation or renaming in configured catalog storage sources to trusted principals.
Scope Backstage's Azure and AWS reader credentials and network access to the intended storage boundaries.
Disable an affected catalog provider if those restrictions cannot be enforced.
// cvss v3.1 vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
Attack vector
Network
Attack complexity
High
Privileges required
High
User interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Checked 2026-10-07 at 23:56 UTC. The most recent advisory here was published 2026-10-07. Updated continuously from NVD, GHSA, OSV and CNA feeds.