Skip to content

Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow`

Low severity GitHub Reviewed Published Jan 21, 2026 in backstage/backstage • Updated Jan 22, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts