Executive brief
Backstage is an open-source platform used to build internal developer portals. The FetchUrlReader component, which fetches catalog and plugin content from URLs, automatically follows HTTP redirects without validating the final destination. An attacker controlling a whitelisted host can craft a redirect chain to bypass URL allowlists and access internal resources, potentially exposing sensitive data or internal APIs.
Technical details
The FetchUrlReader component in Backstage automatically follows HTTP 3xx redirects when fetching remote content for the catalog and other plugins. A server-side request forgery (SSRF) vulnerability exists because redirect destinations are not validated against the `backend.reading.allow` allowlist. An attacker who controls a host listed in the allowlist can issue a redirect to an internal or sensitive URL not on the allowlist, bypassing the security control. The attack requires the attacker to control an allowed host and knowledge of the network topology; attackers cannot inject additional HTTP headers. Patches are available in @backstage/backend-defaults 0.12.2, 0.13.2, 0.14.1, and 0.15.0.
Affected products
- Backstage backend-defaults < 0.12.2, >= 0.13.0 and < 0.13.2, >= 0.14.0 and < 0.14.1
Timeline
- 2026-01-21: disclosed
- 2026-01-21: patched: Patches released for versions 0.12.2, 0.13.2, 0.14.1, and 0.15.0