CVE-2026-73563
Description
A flaw was found in the @backstage/plugin-auth-backend component of Backstage. This vulnerability allows an unauthenticated remote attacker to bypass the redirect_uri allowlist in the experimental dynamic client registration feature. By crafting a malicious redirect Uniform Resource Identifier (URI) with a trusted hostname suffix, an attacker can receive an OAuth authorization code, potentially leading to an account takeover. This issue affects deployments that have enabled the experimental features and configured custom wildcard-hostname or protocol-less patterns.
Statement
Red Hat Developer Hub (RHDH) and Ansible Automation Portal ship @backstage/plugin-auth-backend, which contains this vulnerability. However, the affected features (experimental dynamic client registration and client ID metadata documents) are disabled by default. Only deployments that have explicitly enabled these experimental features and configured custom wildcard-hostname or protocol-less patterns in their allowlists are vulnerable. Default RHDH configurations are not affected.
Mitigation
Do not enable the experimental dynamic client registration or client ID metadata document features. If these features are currently enabled, review and restrict the allowedRedirectUriPatterns and allowedClientIdPatterns configurations to use fully qualified hostnames with explicit protocols rather than wildcard or protocol-less patterns.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 4.7 | N/A | 4.7 |
| Attack Vector | Network | N/A | Network |
| Attack Complexity | High | N/A | Low |
| Privileges Required | None | N/A | None |
| User Interaction | Required | N/A | Required |
| Scope | Changed | N/A | Changed |
| Confidentiality | Low | N/A | Low |
| Integrity Impact | Low | N/A | None |
| Availability Impact | None | N/A | None |
Vector
Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.