Description

A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user can inject specially crafted input into API requests, which disrupts backend query processing. This results in the entire Backstage application crashing and restarting, leading to a platform-wide Denial of Service (DoS). As a result, legitimate users temporarily lose access to the platform.

INFO

Published Date :

2026-02-25T11:25:55.016Z

Last Modified :

2026-02-25T16:29:48.062Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-3118 vulnerability.

Vendors Products
Redhat
  • Rhdh
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-3118.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact