Disclosure summary
### Impact Deployments using event-driven updates in the Bitbucket Server catalog provider may ingest catalog locations from repositories that are excluded by the provider's configured project, repository, or archived-repository filters. An authenticated Bitbucket Server user who can push to a filtered-out repository that remains readable by the configured Backstage integration can trigger a legitimate repository event. The affected event path may then add a Location for that repository even though scheduled discovery excludes it. This can cause catalog entities and metadata to be ingested from a repository that the operator did not intend to trust. Deployments that do not enable event support for the Bitbucket Server catalog provider, do not configure repository filters, or whose integration credentials cannot read the filtered-out repositories are not affected. ### Patches Upgrade `@backstage/plugin-catalog-backend-module-bitbucket-server` to version `0.5.15` or later. The fixed package is available in [Backstage v1.55.0](https://github.com/backstage/backstage/releases/tag/v1.55.0). ### Workarounds - Disable event-driven updates for the Bitbucket Server catalog provider and rely
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-c36c-cf6r-ghgj
Open original source · Updated Oct 07, 2026
Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @backstage/plugin-catalog-backend-module-bitbucket-server | >= 0.4.0, < 0.5.15 | 0.5.15 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T16:25:08-04:00
MODIFIED 2026-10-07T16:25:09-04:00
INGESTED 2026-10-08T12:30:39-04:00