feat(deps): update dependency @backstage/plugin-auth-backend ( 0.25.6 ➔ 0.29.2 ) [security] #85
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/backstage-application!85
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/npm-backstage-plugin-auth-backend-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
^0.25.6→^0.29.0🔒 Security update: prioritize review and verify the vulnerable component is actually deployed.
Merge Confidence badges are included where supported — low or neutral confidence warrants a manual impact check before merge.
Releasedis the upstream publish time.—means this datasource reports no release timestamp — normal for ghcr.io, quay.io and private/proxy registries — sominimumReleaseAgecannot hold the update back and it is eligible as soon as checks pass. A real date means the soak is enforced: add this update type'sminimumReleaseAgetoReleasedto get the eligibility moment.@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch
CVE-2026-32236 / GHSA-qp4c-xg64-7c6x
More information
Details
Impact
A Server-Side Request Forgery (SSRF) vulnerability exists in
@backstage/plugin-auth-backendwhenauth.experimentalClientIdMetadataDocuments.enabledis set totrue. The CIMDmetadata fetch validates the initial
client_idhostname against private IP ranges but does not apply the same validation after HTTP redirects.The practical impact is limited. The attacker cannot read the response body from the internal request, cannot control request headers or method, and the feature must be explicitly
enabled via an experimental flag that is off by default. Deployments that restrict
allowedClientIdPatternsto specific trusted domains are not affected.Patches
Patched in
@backstage/plugin-auth-backendversion0.27.1. The fix disables HTTP redirect following when fetching CIMD metadata documents.Workarounds
Disable the experimental CIMD feature by removing or setting
auth.experimentalClientIdMetadataDocuments.enabledtofalsein your app-config. This is the default configuration.Alternatively, restrict
allowedClientIdPatternsto specific trusted domains rather than using the default wildcard pattern.References
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:UReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass
CVE-2026-32235 / GHSA-wqvh-63mv-9w92
More information
Details
Impact
The experimental OIDC provider in
@backstage/plugin-auth-backendis vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configuredallowedRedirectUriPatternsare affected.A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token.
This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default.
Patches
Upgrade to
@backstage/plugin-auth-backendversion 0.27.1 or later.Workarounds
Disable experimental Dynamic Client Registration and Client ID Metadata Documents features if they are not required.
References
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via
redirect_uriallowlist bypassCVE-2026-73563 / GHSA-38hq-7x33-php4
More information
Details
Impact
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in
@backstage/plugin-auth-backendmatched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern such ashttps://*.example.com/callback, intended to allow subdomains of a trusted host, would also match an attacker-controlled URL such ashttps://attacker.example/x.example.com/callback. This applies toauth.experimentalDynamicClientRegistration.allowedRedirectUriPatternsas well as theallowedClientIdPatternsandallowedRedirectUriPatternsoptions ofauth.experimentalClientIdMetadataDocuments.An attacker could use this to register an OAuth client whose redirect URI points to a host they control while still passing the allowlist, causing authorization codes to be delivered to the attacker when a victim completes an authorization flow. In addition, allowlist patterns without an explicit protocol could match URLs with any protocol, and redirect URIs containing embedded credentials (user:pass@host) were accepted after the credentials were stripped for matching.
The practical impact is limited. Both features are experimental and disabled by default, and the default allowlist patterns only reference fixed or loopback hosts and are not affected. Deployments are only impacted if they enable one of these features and configure custom allowlist patterns that contain a wildcard in the hostname, or patterns without an explicit protocol.
Patches
Patched in
@backstage/plugin-auth-backendversion0.29.2. Patterns are now matched against each URL component separately so that wildcards no longer match across the host and path boundary, patterns without an explicit protocol are rejected as invalid configuration, and redirect URIs with embedded credentials are always rejected.Note that as part of this fix, a wildcard port no longer implicitly matches every path: a pattern such as
http://localhost:*now only matches the root path. Usehttp://localhost:*/*to allow any port and any path.Workarounds
Disable the experimental features by removing
auth.experimentalDynamicClientRegistrationandauth.experimentalClientIdMetadataDocumentsfrom yourapp-config, which is the default configuration. Alternatively, restrict the configured allowlist patterns to fully specified URLs with an explicit protocol and no wildcard in the hostname, which are not affected by this vulnerability.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/plugin-auth-backend)
v0.29.2Compare Source
Patch Changes
e2b3472: Promoted Client ID Metadata Documents (CIMD) to the stableauth.clientIdMetadataDocumentsconfiguration. The previousauth.experimentalClientIdMetadataDocumentskey remains supported as a deprecated alias. Dynamic Client Registration now logs a deprecation warning when enabled and users should migrate to CIMD.2aeb246: Added token revocation support for clients using client ID metadata documents (CIMD). The/v1/revokeendpoint is now available whenever dynamic client registration or client ID metadata documents are enabled, and is advertised throughrevocation_endpointin the OpenID provider configuration.v0.29.1Compare Source
Patch Changes
v0.29.0Compare Source
Minor Changes
29d398b: BREAKING: Hardened the default allowed patterns for CIMD and DCR to replace the previous permissive['*']wildcards with specific defaults for known MCP clients. If you previously relied on the default['*']patterns, you will need to explicitly configure the patterns you need in yourapp-config.yaml.CIMD (
experimentalClientIdMetadataDocuments):allowedClientIdPatternsnow defaults to Claude, VS Code, and the built-in Backstage CLI instead of['*']allowedRedirectUriPatternsnow defaults to loopback addresses (localhost, 127.0.0.1, [::1]) instead of['*']DCR (
experimentalDynamicClientRegistration):allowedRedirectUriPatternsnow defaults to Cursor and loopback addresses instead of['*']If you need to allow additional clients or redirect URIs, you can override these defaults in your
app-config.yaml:Patch Changes
9f269d7: Limit the size of fetched client ID metadata documents to prevent oversized responses from being accepted.3f5e7ec: Improved OIDC error messages to include the rejected redirect URI or client ID, making it easier to debug client registration failures.e9b78e9: Removed theuuiddependency and replaced usage with the built-incrypto.randomUUID().27f24a9: Refresh token usage now verifies that the user's catalog entity still exists before issuing a new access token. If the user has been removed from the catalog, the refresh is rejected and the session is revoked. Transient catalog errors reject the refresh but preserve the session for retry. This check can be disabled by settingauth.experimentalRefreshToken.dangerouslyDisableCatalogPresenceChecktotrue.4f62755: Improved the OAuth consent dialog for MCP authorization by showing more client details, including the client metadata host for CIMD clients, the metadata URL, callback URL, and requested scopes.v0.28.0Compare Source
Minor Changes
d7c67cd: BREAKING: The settingauth.omitIdentityTokenOwnershipClaimhas had its default value switched totrue.With this setting Backstage user tokens issued by the
authbackend will no longer contain anentclaim - the one with the user's ownership entity refs. This means that tokens issued in large orgs no longer risk hitting HTTP header size limits.To get ownership info for the current user, code should use the
userInfocore service. In practice code will typically already conform to this since theentclaim has not been readily exposed in any other way for quite some time. But code which explicitly decodes Backstage tokens - which is strongly discouraged - may be affected by this change.The setting will remain for some time to allow it to be set back to
falseif need be, but it will be removed entirely in a future release.Patch Changes
482ceed: Migrated fromassertErrortotoErrorfor error handling.dc87ac1: Fixed CIMD redirect URI matching to allow any port for localhost addresses per RFC 8252 Section 7.3. Native CLI clients use ephemeral ports for OAuth callbacks, which are now accepted when the registered redirect URI uses a localhost address.v0.27.3Compare Source
v0.27.2Compare Source
Patch Changes
1ccad86: Addedwho-am-iaction to the auth backend actions registry. Returns the catalog entity and user info for the currently authenticated user.d0f4cd2: Added optional client metadata document endpoint at/.well-known/oauth-client/cli.jsonrelative to the auth backend base URL for CLI authentication. Enabled whenauth.experimentalClientIdMetadataDocuments.enabledis set totrue.6738cf0: build(deps): bumpminimatchfrom 9.0.5 to 10.2.1e9b6e97: Fixed a security vulnerability where the CIMD metadata fetch could follow HTTP redirects to internal hosts, bypassing SSRF protections.0f9d673: Improved redirect URI validation in the experimental OIDC provider to match against normalized URLs rather than raw strings.a49a40d: Updated dependencyzodto^3.25.76 || ^4.0.0& migrated to/v3or/v4imports.634eded: Fixed a foreign key constraint violation when issuing refresh tokens for CIMD clients, andprevented a failed refresh token issuance from failing the entire token exchange.
Fixed AWS ALB auth provider incorrectly returning HTTP 500 instead of 401 for JWT validation failures,
which caused retry loops and memory pressure under load.
619be54: Update migrations to be reversiblev0.27.1Compare Source
Patch Changes
d0f4cd2: Added optional client metadata document endpoint at/.well-known/oauth-client/cli.jsonrelative to the auth backend base URL for CLI authentication. Enabled whenauth.experimentalClientIdMetadataDocuments.enabledis set totrue.v0.27.0Compare Source
Minor Changes
31de2c9: Added experimental support for Client ID Metadata Documents (CIMD).This allows Backstage to act as an OAuth 2.0 authorization server that supports the IETF Client ID Metadata Document draft. External OAuth clients can use HTTPS URLs as their
client_id, and Backstage will fetch metadata from those URLs to validate the client.Configuration example:
Clients using CIMD must host a JSON metadata document at their
client_idURL containing at minimum:d0786b9: Added experimental support for refresh tokens via theauth.experimentalRefreshToken.enabledconfiguration option. When enabled, clients can request theoffline_accessscope to receive refresh tokens that can be used to obtain new access tokens without re-authentication.Patch Changes
7dc3dfe: Removed theauth.experimentalDynamicClientRegistration.tokenExpirationconfig option. DCR tokens now use the default 1 hour expiration.If you need longer-lived access, use refresh tokens via the
offline_accessscope instead. DCR clients should already have theoffline_accessscope available. Enable refresh tokens by setting:7455dae: Use node prefix on native importsUpdated dependencies
v0.26.0Compare Source
Minor Changes
7ffc873: Fixuser_created_atmigration causingSQLiteErrorregarding use of non-constants for defaultsPatch Changes
v0.25.7Compare Source
Patch Changes
de96a60: chore(deps): bumpexpressfrom 4.21.2 to 4.22.0Configuration
📅 Schedule: (in timezone Europe/Amsterdam)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate.
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.