Threats Tagged 'cve-2026-32235'
View all threats tagged with 'cve-2026-32235'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-32235'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: Red Hat Developer Hub 1.10.0 release.CVE-2026-2950 0 Red Hat Developer Hub (RHDH) is Red Hat's enterprise-grade, self-managed, customizable developer portal based on Backstage.io. RHDH is supported on OpenShift and other major Kubernetes clusters (AKS, EKS, GKE). The core features of RHDH include a single pane of glass, a centralized software catalog, self-service via golden path templates, and Tech Docs. RHDH is extensible by plugins. Join the discussion | GCVE Database | 06/09/2026, 14:38:34 UTC Added: 06/10/2026, 11:50:14 UTC |
CVE-2026-32235: CWE-601: URL Redirection to Untrusted Site ('Open Redirect') in @backstage plugin-auth-backendCVE-2026-32235 0 Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured allowedRedirectUriPatterns are affected. A specially crafted redirect URI can pass the allowlist validation while resolving to an attacker-controlled host. If a victim approves the resulting OAuth consent request, their authorization code is sent to the attacker, who can exchange it for a valid access token. This requires victim interaction and that one of the experimental features is explicitly enabled, which is not the default. This vulnerability is fixed in 0.27.1. Join the discussion | CVE Database V5 | 03/12/2026, 18:35:06 UTC Added: 03/12/2026, 19:00:32 UTC |
Showing 1 to 2 of 2 results