{"api_version":"v1","generated_at":"2026-10-07T11:30:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-backstage-plugin-auth-backend-1001e738e516","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"plugin-auth-backend","next_cursor":null,"observations":[{"affected":"< 0.27.1","affected_versions_present":true,"cve_id":"CVE-2026-32236","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32236","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-04-15T20:46:50.517Z","patch_url":"https://github.com/backstage/backstage/commit/17038abf2dfdb4abc08a59b1c95af39851de0e07","primary_source":"","published":"2026-03-12T18:37:11.330Z"},{"affected":"< 0.27.1","affected_versions_present":true,"cve_id":"CVE-2026-32235","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32235","fixed":"For more about Red Hat Developer Hub, see References links","last_modified":"2026-03-12T20:46:46.618Z","patch_url":"https://access.redhat.com/security/cve/CVE-2026-32235","primary_source":"","published":"2026-03-12T18:35:06.325Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"@backstage"}}
