StackRadar

CVE-2026-106562

Medium

Advisory

Published 7 Oct 2026In the index since 8 Oct 2026
Severity
Medium
worst across findings
CVSS
4.3
base score, highest
EPSS
0.002
9th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
4
of 18,071 indexed, latest versions
Container images
4
deployed by those charts
Fix available
2 of 2
affected packages

Backstage has incorrect authorization in search engine permission filtering

Carried by container images the latest versions of 4 of 18,071 indexed charts deploy, on 4 images.

Affected packageAffected versionsFixed inImages
@backstage/plugin-search-backendnpm0.2.3, 1.5.3, 2.1.0, 2.1.32.1.64
@backstage/plugin-search-backend-module-elasticsearchnpm0.0.11.8.71
OSV records
GHSA-9325-vq29-gp3v

Charts affected

4 by stars
ChartLatestAffected imagesRadar Score
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-106562.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
@backstage/plugin-search-backend@2.1.0
2.1.6

Open the chart page →

1,934
backstageirembo-backstage-helmVerified publisher1.0.51 of 3See more

backstage irembo-backstage-helm 1.0.5

1 of the 3 container images this version deploys carry CVE-2026-106562.

Container imageDigestPackageFixed in
roadiehq/community-backstage-image:latestef355bf5b639
@backstage/plugin-search-backend@0.2.3
@backstage/plugin-search-backend-module-elasticsearch@0.0.1
2.1.6
1.8.7

Open the chart page →

8,786
backstagemcwarmanVerified publisher0.10.101 of 2See more

backstage mcwarman 0.10.10

1 of the 2 container images this version deploys carry CVE-2026-106562.

Container imageDigestPackageFixed in
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
@backstage/plugin-search-backend@1.5.3
2.1.6

Open the chart page →

11,205
devportalveecode-platform-nextVerified publisher1.0.31 of 1See more

devportal veecode-platform-next 1.0.3

1 of the 1 container images this version deploys carry CVE-2026-106562.

Container imageDigestPackageFixed in
veecode/devportaldigest-pinnede5c84f744994
@backstage/plugin-search-backend@2.1.3
2.1.6

Open the chart page →

1,792

Container images carrying it

4 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
roadiehq/community-backstage-image:latestef355bf5b639
@backstage/plugin-search-backend@0.2.3
@backstage/plugin-search-backend-module-elasticsearch@0.0.1
2.1.6
1.8.7
1
veecode/devportale5c84f744994
@backstage/plugin-search-backend@2.1.3
2.1.6
1
ghcr.io/mcwarman/backstage-sample-app/backend:main07aba09a594f
@backstage/plugin-search-backend@1.5.3
2.1.6
1
quay.io/rhdh/rhdh-hub-rhel9:latest4f8c0f8a8ee0
@backstage/plugin-search-backend@2.1.0
2.1.6
1

syft 1.42.1 · advisories as of 9 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.