Where
-Infinity
0

webpack webpack-dev-serverwebpack-dev-server vulnerable to denial of service via a malformed Host or Origin header

Risk 27
Severity
5.3
First published (updated )

webpack webpack-dev-serverwebpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints

Risk 24
Severity
4.7
First published (updated )

npm/webpack-dev-serverwebpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

Risk 19
Severity
5.3
EPSS
0.16%
First published (updated )

npm/webpack-dev-serverwebpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins

Risk 37
Severity
6.5
First published (updated )

npm/webpackwebpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

Risk 25
Severity
3.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/webpackwebpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects

Risk 25
Severity
3.7
First published (updated )

webpack webpack-dev-serverwebpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser

Risk 41
Severity
7.5
First published (updated )

webpack webpack-dev-serverwebpack-dev-server users' source code may be stolen when they access a malicious web site

Risk 35
Severity
5.9
First published (updated )

npm/webpackDOM Clobbering Gadget found in Webpack's AutoPublicPathRuntimeModule that leads to Cross-site Scripting (XSS)

Risk 54
Severity
6.4
First published (updated )

npm/webpack-dev-middlewarewebpack-dev-middleware Path Traversal vulnerability

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/webpackWebpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles t…

Risk 87
Severity
9.8
First published (updated )

IBM Data Virtualization on Cloud Pak for DataPrototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils 2.…

Risk 89
Severity
9.8
First published (updated )

npm/loader-utilsA Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpo…

Risk 46
Severity
7.5
First published (updated )

redhat/rh-sso7-keycloakA Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpo…

Risk 45
Severity
7.5
First published (updated )

webpack.js webpack-dev-serverInput Validation

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203