Skip to content

Update dependency webpack-dev-server to v5.2.6 [SECURITY] - autoclosed - #572

Closed
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-webpack-dev-server-vulnerability
Closed

Update dependency webpack-dev-server to v5.2.6 [SECURITY] - autoclosed#572
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-webpack-dev-server-vulnerability

Conversation

@renovate

@renovate renovate Bot commented May 20, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
webpack-dev-server 5.2.25.2.6 age confidence

webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins

CVE-2026-6402 / GHSA-79cf-xcqc-c78w

More information

Details

Impact

When webpack-dev-server is running on a non-HTTPS origin (the default), cross-origin requests from malicious websites can load the dev server's JavaScript bundles via <script> tags. The fix introduced in v5.2.1 (CVE-2025-30359) relied on Sec-Fetch-Mode and Sec-Fetch-Site request headers to block these requests, but browsers only send these headers for potentially trustworthy origins. Over plain HTTP, the headers are absent and the check is bypassed.

An attacker who knows the dev server's host, port, and output path can exfiltrate all module source code by intercepting the webpack runtime's module registration.

This does not affect Chrome 142+ (and other Chromium-based browsers) due to local network access restrictions.

Patches

Patched in webpack-dev-server >= 5.2.4 by setting Cross-Origin-Resource-Policy: same-origin on responses.

Workarounds

Run the dev server with HTTPS enabled (--https or server.type: 'https' in config).

Resources

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

CVE-2026-9595 / GHSA-mx8g-39q3-5c79

More information

Details

Impact

When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket).

Patches

Fixed in webpack-dev-server 5.2.5.

Workarounds

Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header

CVE-2026-14631 / GHSA-m28w-2pqf-7qgj

More information

Details

Impact

An unauthenticated peer that can reach the webpack-dev-server process can terminate it by sending either a normal HTTP request with a malformed Host header, or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed header triggers an uncaught exception in the host-validation path and crashes the dev server process.

Patches

Fixed in webpack-dev-server 5.2.6 by treating malformed Host and Origin header values as invalid rather than throwing (see PR #​5699).

Workarounds

Keep the dev server bound to localhost (the default) and do not expose it to untrusted networks.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints

CVE-2026-14620 / GHSA-f5vj-f2hx-8m93

More information

Details

Impact

The internal /webpack-dev-server/open-editor and /webpack-dev-server/invalidate endpoints perform state-changing actions on any GET request, without verifying that the request originated from the dev server's own page. Any website a developer visits while the dev server is running can trigger them cross-origin with no interaction beyond the visit.

An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root (e.g. ~/.ssh/config). The file's contents are not returned to the attacker. Repeated requests can also spawn editor processes and force recompilations, degrading the developer's machine.

Patches

Fixed in webpack-dev-server 5.2.6 by rejecting cross-site requests to the /webpack-dev-server/open-editor and /webpack-dev-server/invalidate endpoints (see PR #​5698).

Workarounds

None

Severity

  • CVSS Score: 4.7 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

webpack/webpack-dev-server (webpack-dev-server)

v5.2.6

Compare Source

Patch Changes
  • fix: allow undefined as the Server constructor options argument again (by @​bjohansebas in #​5695)

    Restores accepting undefined (defaulting it to {}) for the options
    argument, so passing a webpack config's optional devServer field type-checks and works as before.

  • Protect the built-in state-changing routes (/webpack-dev-server/invalidate and /webpack-dev-server/open-editor) against cross-site request forgery. Requests are now checked with Sec-Fetch-Site (falling back to an Origin/Host comparison when it is absent), so a cross-site page can no longer trigger a rebuild or open a file in the editor. Same-origin requests, user-initiated navigations, and non-browser clients (e.g. curl) are unaffected. (by @​bjohansebas in #​5698)

  • Handle malformed Host and Origin header values gracefully when validating requests. (by @​bjohansebas in #​5699)

v5.2.5

Compare Source

Patch Changes
  • Skip the HMR WebSocket path when forwarding upgrade requests to user-defined proxies, so custom proxy WebSocket upgrades are no longer intercepted by the dev server. (by @​bjohansebas in #​5680)

All notable changes to this project will be documented in this file. See standard-version for commit guidelines.

5.2.4 (2026-05-11)
Bug Fixes
  • set Cross-Origin-Resource-Policy header to prevent source code theft over HTTP
5.2.3 (2026-01-12)
Bug Fixes
  • add cause for errorObject (#​5518) (37b033d)
  • compatibility with event target and universal target and lazy compilation (574026c)
  • overlay: add ESC key to dismiss overlay (#​5598) (f91baa8)
  • progress indicator styles (#​5557) (41a53a1)
  • upgrade selfsigned to v5
5.2.2 (2025-06-03)
Bug Fixes

v5.2.4

Compare Source

v5.2.3

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@vercel

vercel Bot commented May 20, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ddr-tools Ready Ready Preview Jul 21, 2026 6:40pm

@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from e4e9eb2 to 7e7abb2 Compare May 28, 2026 18:44
@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 7e7abb2 to 826d538 Compare June 1, 2026 16:52
@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 826d538 to a34e7bc Compare June 10, 2026 03:40
@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from a34e7bc to 9088ecb Compare June 11, 2026 12:01
@renovate renovate Bot changed the title chore(deps): update dependency webpack-dev-server to v5.2.4 [security] chore(deps): update dependency webpack-dev-server to v5.2.5 [security] Jun 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 9088ecb to 10fee32 Compare June 27, 2026 19:49
@renovate renovate Bot changed the title chore(deps): update dependency webpack-dev-server to v5.2.5 [security] Update dependency webpack-dev-server to v5.2.5 [SECURITY] Jul 8, 2026
@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from 10fee32 to fa24e0f Compare July 12, 2026 11:42
@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from fa24e0f to cea686b Compare July 20, 2026 18:55
@renovate
renovate Bot force-pushed the renovate/npm-webpack-dev-server-vulnerability branch from cea686b to fe58de4 Compare July 21, 2026 18:38
@renovate renovate Bot changed the title Update dependency webpack-dev-server to v5.2.5 [SECURITY] Update dependency webpack-dev-server to v5.2.6 [SECURITY] Jul 21, 2026
@renovate renovate Bot changed the title Update dependency webpack-dev-server to v5.2.6 [SECURITY] Update dependency webpack-dev-server to v5.2.6 [SECURITY] - autoclosed Jul 24, 2026
@renovate renovate Bot closed this Jul 24, 2026
@renovate
renovate Bot deleted the renovate/npm-webpack-dev-server-vulnerability branch July 24, 2026 16:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants