Skip to main content

Vendor/product archive

webpack.js / webpack-dev-server CVEs

Beta · best-effort

7 CVEs tagged to webpack.js / webpack-dev-server0 Critical, 1 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2026-14631

Published Jul 3, 2026

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-14620

Published Jul 3, 2026

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-chang…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-9595

Published Jun 15, 2026

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the…

CVSS 5.3 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-6402

Published May 12, 2026

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
28.9
Vendor/product tagsBeta · best-effort

CVE-2025-30360

Published Jun 3, 2025

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-30359

Published Jun 3, 2025

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14732

Published Sep 21, 2018

An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebS…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1