CVE-2026-3118 Details
Description
A security flaw was identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). The issue occurs due to insufficient input validation in GraphQL query handling. An authenticated user can inject specially crafted input into API requests, which disrupts backend query processing. This results in the entire Backstage application crashing and restarting, leading to a platform-wide Denial of Service (DoS). As a result, legitimate users temporarily lose access to the platform.
A GraphQL injection vulnerability has been identified in the Orchestrator Plugin of Red Hat Developer Hub (Backstage). This issue arises from inadequate input validation in GraphQL query processing. An authenticated user can inject malicious input into API requests, disrupting backend query handling. Consequently, the entire Backstage application crashes and restarts, causing a platform-wide denial-of-service (DoS) condition. As a result, legitimate users temporarily lose access to the platform.
To mitigate this vulnerability, restrict network access to the Red Hat Developer Hub instance to trusted users and networks only. This limits exposure of the vulnerable Orchestrator Plugin to unauthorized access.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat developer hub | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 5, 2026 | CVE Modified | [email protected] |
| Apr 22, 2026 | CVE Modified | [email protected] |
| Feb 27, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | New CVE Received | [email protected] |