GPU VulnDB

Database/Control plane, storage & DevOps

Backstage Kubernetes backend: deprecated services endpoint accepts crafted entity data and widens read scope

CVSS 5.3CVE-2026-106563Control plane, storage & DevOpscurated

Impact

The deprecated Kubernetes services endpoint does not properly validate the entity passed to it, so an authenticated user with Kubernetes read permissions can supply crafted entity data and pull workload data outside the scope they were meant to see. Where a portal is the boundary between teams sharing a GPU cluster, this erases that boundary for workload inventory: who is running what, on which cluster, under which namespace. Exposure is limited to read-only access to Kubernetes object metadata across the configured clusters, with no write path and no credential disclosure claimed in the advisory. Attack complexity is rated high, which fits a flaw that needs the attacker to shape entity input to match targets they cannot enumerate directly.

Who can reach it

Authenticated Backstage user with Kubernetes read permissions, over the network, reaching the plugin's deprecated services endpoint.

What to do

Upgrade @backstage/plugin-kubernetes-backend to 0.21.8 (Backstage release 1.54.1) and restart the Backstage backend. Deployments that do not need the deprecated services endpoint should stop calling it; the advisory does not describe a configuration-only mitigation beyond the upgrade.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.