Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.5 LOW
CVE-2026-106487 — Backstage: Unsupported catalog cluster authentication mode in kubernetes backend

Backstage is an open framework for building developer portals. Prior to 0.21.10, the @backstage/plugin-kubernetes-backend package is affected by unsupported catalog cluster authentication mode in kub…

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-106486 — Backstage: Improper filesystem validation in Bitbucket pull-request scaffolder actions

Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module…

backstage_plugin-techdocs-node | Remote | Path Traversal
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.4 MEDIUM
CVE-2026-106463 — Backstage: Improper authorization in GitLab organizational user ingestion

Backstage is an open framework for building developer portals. Prior to 0.8.7, the @backstage/plugin-catalog-backend-module-gitlab package is affected by improper authorization in gitlab organization…

backstage_plugin-techdocs-node | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.4 MEDIUM
CVE-2026-106462 — Backstage: Scaffolder credential handling may allow unintended GitHub authentication fall…

Backstage is an open framework for building developer portals. Prior to 1.54.6, scaffolder source-control actions may not consistently enforce intended credential boundaries. An authenticated user co…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.3 MEDIUM
CVE-2026-106461 — Backstage: Incorrect authorization in scaffolder task listing

Backstage is an open framework for building developer portals. Prior to 4.1.0, the @backstage/plugin-scaffolder-backend package is affected by incorrect authorization in scaffolder task listing. An a…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.8 MEDIUM
CVE-2026-106460 — Backstage: Explicit negative email verification can be ignored during shared OAuth profil…

Backstage is an open framework for building developer portals. From 0.3.0 until 0.6.15 and 0.7.5, the @backstage/plugin-auth-node package did not consistently honor explicit negative email verificati…

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
8.5 HIGH
CVE-2026-106459 — Backstage: Improper input validation in Sentry scaffolder actions

Backstage is an open framework for building developer portals. From 0.3.0 until 0.3.8, the @backstage/plugin-scaffolder-backend-module-sentry package is affected by improper input validation in sentr…

backstage_plugin-techdocs-node | Remote | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.5 MEDIUM
CVE-2026-106458 — Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates

Backstage is an open framework for building developer portals. From 0.4.0 until 0.5.15, the @backstage/plugin-catalog-backend-module-bitbucket-server package is affected by inconsistent repository fi…

backstage_plugin-techdocs-node | Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.8 MEDIUM
CVE-2026-106457 — Backstage: Insufficient audience validation in the Cloudflare Access auth provider

Backstage is an open framework for building developer portals. From 0.1.0 until 0.5.0, the @backstage/plugin-auth-backend-module-cloudflare-access-provider package is affected by insufficient audienc…

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.8 MEDIUM
CVE-2026-106456 — Backstage: Inconsistent credential enforcement for overlapping proxy routes

Backstage is an open framework for building developer portals. From 0.5.0 until 0.6.18, the @backstage/plugin-proxy-backend package is affected by inconsistent credential enforcement for overlapping …

backstage_plugin-techdocs-node | Remote | Authentication
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.7 HIGH
CVE-2026-106455 — Backstage: Improper validation of MkDocs plugin configuration in TechDocs

Backstage is an open framework for building developer portals. From 0.11.12 until 1.14.7 and 1.15.5, the @backstage/plugin-techdocs-node package is affected by improper validation of mkdocs plugin co…

backstage_plugin-techdocs-node | Remote | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
3.1 LOW
CVE-2026-106496 — Backstage: Inconsistent enforcement of allowed location types during catalog processing

Backstage is an open framework for building developer portals. Prior to 3.9.1, the @backstage/plugin-catalog-backend package is affected by inconsistent enforcement of allowed location types during c…

Remote | Misconfiguration
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
0.0 NA
CVE-2026-86684 — Gitea push mirror local path check uses the repository owner

The Gitea push mirror API checked whether the repository owner, instead of the requesting user, may use local file system paths. On instances with `[security] IMPORT_LOCAL_PATHS = true`, a repository…

| Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-106062 — Gimp: gimp: heap buffer overflow in dds loader on crafted directdraw surface file

A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height, and pitch can be computed using 32-bit ari…

enterprise_linux enterprise_linux | Memory Corruption
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
5.7 MEDIUM
CVE-2026-106032 — Server-side request forgery and local file read via unrestricted external OpenAPI referen…

Server-side request forgery in the OpenAPI schema processing of the agent import functionality in Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated remote actor in t…

bedrock-agentcore-starter-toolkit | Remote | Server-Side Request Forgery
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
9.0 CRITICAL
CVE-2026-105812 — Code injection via unencoded configuration values during Python code generation in Bedroc…

Improper control of code generation in the agent import functionality of Amazon Bedrock AgentCore Starter Toolkit before 0.3.14 might allow an authenticated same-account actor to execute arbitrary co…

bedrock-agentcore-starter-toolkit | Remote | Injection
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.1 HIGH
CVE-2026-105811 — Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook s…

Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/ma…

qnabot-on-aws | Remote | Authorization
Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
6.2 MEDIUM
CVE-2026-104046 — Sssd: sssd: denial of service via incomplete identity provider authentication requests

A flaw was found in SSSD (System Security Services Daemon). When Identity Provider (IdP) authentication is enabled, pre-authentication requests retain state in memory without being cleared or timed o…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
4.7 MEDIUM
CVE-2026-104045 — Sssd: sssd: denial of service via race condition in autofs responder

A flaw was found in SSSD. A local user can trigger a Denial of Service (DoS) by exploiting a race condition in the autofs responder between asynchronous enumeration completion and map invalidation. B…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
7.8 HIGH
CVE-2026-101258 — Ghostscript: ghostscript: -dsafer sandbox bypass via type 5 shading oob write and procedu…

A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscrip…

Oct 06, 2026 Oct 06, 2026
Oct 06, 2026
Oct 06, 2026
Showing 20 of 15414 Results