Repository navigation
Update dependency @backstage/plugin-auth-backend to ^0.29.0 [SECURITY] - #11
Open
renovate-wibrow[bot] wants to merge 1 commit into
Open
renovate-wibrow[bot] wants to merge 1 commit into
renovate-wibrow[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.22.6→^0.29.0@backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass
CVE-2026-32235 / GHSA-wqvh-63mv-9w92
More information
Details
Impact
The experimental OIDC provider in
@backstage/plugin-auth-backendis vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configuredallowedRedirectUriPatternsare affected.A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token.
This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default.
Patches
Upgrade to
@backstage/plugin-auth-backendversion 0.27.1 or later.Workarounds
Disable experimental Dynamic Client Registration and Client ID Metadata Documents features if they are not required.
References
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
@backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch
CVE-2026-32236 / GHSA-qp4c-xg64-7c6x
More information
Details
Impact
A Server-Side Request Forgery (SSRF) vulnerability exists in
@backstage/plugin-auth-backendwhenauth.experimentalClientIdMetadataDocuments.enabledis set totrue. The CIMDmetadata fetch validates the initial
client_idhostname against private IP ranges but does not apply the same validation after HTTP redirects.The practical impact is limited. The attacker cannot read the response body from the internal request, cannot control request headers or method, and the feature must be explicitly
enabled via an experimental flag that is off by default. Deployments that restrict
allowedClientIdPatternsto specific trusted domains are not affected.Patches
Patched in
@backstage/plugin-auth-backendversion0.27.1. The fix disables HTTP redirect following when fetching CIMD metadata documents.Workarounds
Disable the experimental CIMD feature by removing or setting
auth.experimentalClientIdMetadataDocuments.enabledtofalsein your app-config. This is the default configuration.Alternatively, restrict
allowedClientIdPatternsto specific trusted domains rather than using the default wildcard pattern.References
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:UReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via
redirect_uriallowlist bypassCVE-2026-73563 / GHSA-38hq-7x33-php4
More information
Details
Impact
The allowlist matching used by the experimental dynamic client registration and client ID metadata document (CIMD) features in
@backstage/plugin-auth-backendmatched glob patterns against the full URL string. A * wildcard could therefore match across URL component boundaries: a pattern such ashttps://*.example.com/callback, intended to allow subdomains of a trusted host, would also match an attacker-controlled URL such ashttps://attacker.example/x.example.com/callback. This applies toauth.experimentalDynamicClientRegistration.allowedRedirectUriPatternsas well as theallowedClientIdPatternsandallowedRedirectUriPatternsoptions ofauth.experimentalClientIdMetadataDocuments.An attacker could use this to register an OAuth client whose redirect URI points to a host they control while still passing the allowlist, causing authorization codes to be delivered to the attacker when a victim completes an authorization flow. In addition, allowlist patterns without an explicit protocol could match URLs with any protocol, and redirect URIs containing embedded credentials (user:pass@host) were accepted after the credentials were stripped for matching.
The practical impact is limited. Both features are experimental and disabled by default, and the default allowlist patterns only reference fixed or loopback hosts and are not affected. Deployments are only impacted if they enable one of these features and configure custom allowlist patterns that contain a wildcard in the hostname, or patterns without an explicit protocol.
Patches
Patched in
@backstage/plugin-auth-backendversion0.29.2. Patterns are now matched against each URL component separately so that wildcards no longer match across the host and path boundary, patterns without an explicit protocol are rejected as invalid configuration, and redirect URIs with embedded credentials are always rejected.Note that as part of this fix, a wildcard port no longer implicitly matches every path: a pattern such as
http://localhost:*now only matches the root path. Usehttp://localhost:*/*to allow any port and any path.Workarounds
Disable the experimental features by removing
auth.experimentalDynamicClientRegistrationandauth.experimentalClientIdMetadataDocumentsfrom yourapp-config, which is the default configuration. Alternatively, restrict the configured allowlist patterns to fully specified URLs with an explicit protocol and no wildcard in the hostname, which are not affected by this vulnerability.Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
backstage/backstage (@backstage/plugin-auth-backend)
v0.29.2Compare Source
Patch Changes
e2b3472: Promoted Client ID Metadata Documents (CIMD) to the stableauth.clientIdMetadataDocumentsconfiguration. The previousauth.experimentalClientIdMetadataDocumentskey remains supported as a deprecated alias. Dynamic Client Registration now logs a deprecation warning when enabled and users should migrate to CIMD.2aeb246: Added token revocation support for clients using client ID metadata documents (CIMD). The/v1/revokeendpoint is now available whenever dynamic client registration or client ID metadata documents are enabled, and is advertised throughrevocation_endpointin the OpenID provider configuration.v0.29.1Compare Source
Patch Changes
v0.29.0Compare Source
Minor Changes
29d398b: BREAKING: Hardened the default allowed patterns for CIMD and DCR to replace the previous permissive['*']wildcards with specific defaults for known MCP clients. If you previously relied on the default['*']patterns, you will need to explicitly configure the patterns you need in yourapp-config.yaml.CIMD (
experimentalClientIdMetadataDocuments):allowedClientIdPatternsnow defaults to Claude, VS Code, and the built-in Backstage CLI instead of['*']allowedRedirectUriPatternsnow defaults to loopback addresses (localhost, 127.0.0.1, [::1]) instead of['*']DCR (
experimentalDynamicClientRegistration):allowedRedirectUriPatternsnow defaults to Cursor and loopback addresses instead of['*']If you need to allow additional clients or redirect URIs, you can override these defaults in your
app-config.yaml:Patch Changes
9f269d7: Limit the size of fetched client ID metadata documents to prevent oversized responses from being accepted.3f5e7ec: Improved OIDC error messages to include the rejected redirect URI or client ID, making it easier to debug client registration failures.e9b78e9: Removed theuuiddependency and replaced usage with the built-incrypto.randomUUID().27f24a9: Refresh token usage now verifies that the user's catalog entity still exists before issuing a new access token. If the user has been removed from the catalog, the refresh is rejected and the session is revoked. Transient catalog errors reject the refresh but preserve the session for retry. This check can be disabled by settingauth.experimentalRefreshToken.dangerouslyDisableCatalogPresenceChecktotrue.4f62755: Improved the OAuth consent dialog for MCP authorization by showing more client details, including the client metadata host for CIMD clients, the metadata URL, callback URL, and requested scopes.v0.28.0Compare Source
Minor Changes
d7c67cd: BREAKING: The settingauth.omitIdentityTokenOwnershipClaimhas had its default value switched totrue.With this setting Backstage user tokens issued by the
authbackend will no longer contain anentclaim - the one with the user's ownership entity refs. This means that tokens issued in large orgs no longer risk hitting HTTP header size limits.To get ownership info for the current user, code should use the
userInfocore service. In practice code will typically already conform to this since theentclaim has not been readily exposed in any other way for quite some time. But code which explicitly decodes Backstage tokens - which is strongly discouraged - may be affected by this change.The setting will remain for some time to allow it to be set back to
falseif need be, but it will be removed entirely in a future release.Patch Changes
482ceed: Migrated fromassertErrortotoErrorfor error handling.dc87ac1: Fixed CIMD redirect URI matching to allow any port for localhost addresses per RFC 8252 Section 7.3. Native CLI clients use ephemeral ports for OAuth callbacks, which are now accepted when the registered redirect URI uses a localhost address.v0.27.3Compare Source
v0.27.2Compare Source
Patch Changes
1ccad86: Addedwho-am-iaction to the auth backend actions registry. Returns the catalog entity and user info for the currently authenticated user.d0f4cd2: Added optional client metadata document endpoint at/.well-known/oauth-client/cli.jsonrelative to the auth backend base URL for CLI authentication. Enabled whenauth.experimentalClientIdMetadataDocuments.enabledis set totrue.6738cf0: build(deps): bumpminimatchfrom 9.0.5 to 10.2.1e9b6e97: Fixed a security vulnerability where the CIMD metadata fetch could follow HTTP redirects to internal hosts, bypassing SSRF protections.0f9d673: Improved redirect URI validation in the experimental OIDC provider to match against normalized URLs rather than raw strings.a49a40d: Updated dependencyzodto^3.25.76 || ^4.0.0& migrated to/v3or/v4imports.634eded: Fixed a foreign key constraint violation when issuing refresh tokens for CIMD clients, andprevented a failed refresh token issuance from failing the entire token exchange.
Fixed AWS ALB auth provider incorrectly returning HTTP 500 instead of 401 for JWT validation failures,
which caused retry loops and memory pressure under load.
619be54: Update migrations to be reversiblev0.27.1Compare Source
Patch Changes
d0f4cd2: Added optional client metadata document endpoint at/.well-known/oauth-client/cli.jsonrelative to the auth backend base URL for CLI authentication. Enabled whenauth.experimentalClientIdMetadataDocuments.enabledis set totrue.v0.27.0Compare Source
Minor Changes
31de2c9: Added experimental support for Client ID Metadata Documents (CIMD).This allows Backstage to act as an OAuth 2.0 authorization server that supports the IETF Client ID Metadata Document draft. External OAuth clients can use HTTPS URLs as their
client_id, and Backstage will fetch metadata from those URLs to validate the client.Configuration example:
Clients using CIMD must host a JSON metadata document at their
client_idURL containing at minimum:{ "client_id": "https://example.com/.well-known/oauth-client/my-app", "client_name": "My Application", "redirect_uris": ["http://localhost:8080/callback"], "token_endpoint_auth_method": "none" }d0786b9: Added experimental support for refresh tokens via theauth.experimentalRefreshToken.enabledconfiguration option. When enabled, clients can request theoffline_accessscope to receive refresh tokens that can be used to obtain new access tokens without re-authentication.Patch Changes
7dc3dfe: Removed theauth.experimentalDynamicClientRegistration.tokenExpirationconfig option. DCR tokens now use the default 1 hour expiration.If you need longer-lived access, use refresh tokens via the
offline_accessscope instead. DCR clients should already have theoffline_accessscope available. Enable refresh tokens by setting:7455dae: Use node prefix on native importsUpdated dependencies
v0.26.0Compare Source
Minor Changes
7ffc873: Fixuser_created_atmigration causingSQLiteErrorregarding use of non-constants for defaultsPatch Changes
v0.25.7Compare Source
Patch Changes
de96a60: chore(deps): bumpexpressfrom 4.21.2 to 4.22.0v0.25.6Compare Source
Patch Changes
a9315d0: Change internalstatecolumn totextto support state of over 255 characters05f60e1: Refactored constructor parameter properties to explicit property declarations for compatibility with TypeScript'serasableSyntaxOnlysetting. This internal refactoring maintains all existing functionality while ensuring TypeScript compilation compatibility.51ff7d8: Allow configuring dynamic client registration token expiration with configauth.experimentalDynamicClientRegistration.tokenExpiration.Maximum expiration for the DCR token is 24 hours. Default expiration is 1 hour.
Updated dependencies
v0.25.5Compare Source
Patch Changes
v0.25.4Compare Source
Patch Changes
1d47bf3: Implementing Dynamic Client Registration with the OIDC server. You can enable this by settingauth.experimentalDynamicClientRegistration.enabledinapp-config.yaml. This is highly experimental, but feedback welcome.54ddfef: Updating plugin metadatav0.25.3Compare Source
Patch Changes
v0.25.2Compare Source
Patch Changes
e88cb70: Small internal refactor to move out theuserInfodatabase from thetokenIssuer. Also removesexpfrom being stored inUserInfoand it's now replaced withcreated_atandupdated_atin the database instead.207778c: Internal refactor of OIDC endpoints andUserInfoDatabasev0.25.1Compare Source
Patch Changes
v0.25.0Compare Source
Minor Changes
57221d9: BREAKING: Removed support for the old backend system, and removed all deprecated exports.If you were using one of the deprecated imports from this package, you will have to follow the instructions in their respective deprecation notices before upgrading. Most of the general utilities are available from
@backstage/plugin-auth-node, and the specific auth providers are available from dedicated packages such as for example@backstage/plugin-auth-backend-module-github-provider. See the auth docs for specific instructions.Patch Changes
0d606ac: Added the configuration flagauth.omitIdentityTokenOwnershipClaimthat causes issued user tokens to no longer contain theentclaim that represents the ownership references of the user.The benefit of this new flag is that issued user tokens will be much smaller in
size, but they will no longer be self-contained. This means that any consumers
of the token that require access to the ownership claims now need to call the
/api/auth/v1/userinfoendpoint instead. Within the Backstage ecosystem this isdone automatically, as clients will still receive the full set of claims during
authentication, while plugin backends will need to use the
UserInfoServicewhich already calls the user info endpoint if necessary.
When enabling this flag, it is important that any custom sign-in resolvers directly return the result of the sign-in method. For example, the following would not work:
Instead, the sign-in resolver should directly return the result:
72d019d: Removed various typosab53e6f: Added support for the newdangerousEntityRefFallbackoption forsignInWithCatalogUserinAuthResolverContext.b128ed9: Thestatickey store now issues tokens with the same structure as other key stores. Tokens now include thetypfield in the header and theuip(user identity proof) in the payload.Updated dependencies
v0.24.5Compare Source
Patch Changes
25d05f9: Slight update to the config schemav0.24.4Compare Source
Patch Changes
7956beb: Marked the remaining exports related tocreateRouterand the old backend system as deprecated.For more information about migrating to the new backend system, see the migration guide.
Support for the old backend system will be removed in the next release of this plugin.
b6702ea: DeprecatedgetDefaultOwnershipEntityRefsin favor of the new.resolveOwnershipEntityRefs(...)method in theAuthResolverContext.The following code in a custom sign-in resolver:
Can be replaced with the following:
Updated dependencies
v0.24.3Compare Source
Patch Changes
v0.24.2Compare Source
Patch Changes
8379bf4: Remove usages ofPluginDatabaseManagerandPluginEndpointDiscoveryand replace with their equivalent service typesv0.24.1Compare Source
Patch Changes
c907440: Improved error forwarding for OAuth refresh endpoints40518ab: Fix issue withjwksendpoint returning invalid data withfirestore5c9cc05: Use native fetch instead of node-fetchv0.24.0Compare Source
Minor Changes
75168e3: BREAKING: The AWS ALBfullProfilewill no longer have the its username or email converted to lowercase. This is to ensure unique handling of the users. You may need to update and configure a custom sign-in resolver or profile transform as a result.Patch Changes
d52d7f9: Support ISO and ms string forms of durations in config too4e58bc7: Upgrade to uuid v11 internallyv0.23.1Compare Source
Patch Changes
094eaa3: Remove references to in-repo backend-commonv0.23.0Compare Source
Minor Changes
d425fc4: BREAKING: The return values fromcreateBackendPlugin,createBackendModule, andcreateServiceFactoryare now simplyBackendFeatureandServiceFactory, instead of the previously deprecated form of a function that returns them. For this reason,createServiceFactoryalso no longer accepts the callback form where you provide direct options to the service. This also affects allcoreServices.*service refs.This may in particular affect tests; if you were effectively doing
createBackendModule({...})()(note the parentheses), you can now remove those extra parentheses at the end. You may encounter cases of this in yourpackages/backend/src/index.tstoo, where you add plugins, modules, and services. If you were usingcreateServiceFactorywith a function as its argument for the purpose of passing in options, this pattern has been dConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.