Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webpack Dev Server MEDIUM 5.3
CVE-2026-14631

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request wit…

Fix: 5.2.6+
Fix from $1,600 2026-07-03
Webpack Dev Server MEDIUM 6.5
CVE-2026-6402

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustwo…

Fix: 5.2.4+
Fix from $1,600 2026-05-12
Webpack Dev Server MEDIUM 6.5
CVE-2025-30360

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server use…

Fix: 5.2.1+
Fix from $1,600 2025-06-03
Webpack Dev Server MEDIUM 5.9
CVE-2025-30359

webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server use…

Fix: 5.2.1+
Fix from $1,600 2025-06-03
Webpack MEDIUM 6.1
CVE-2024-43788

Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling,…

Fix: 5.94.0+
Fix from $1,600 2024-08-27
Webpack Dev Middleware HIGH 7.5
CVE-2024-29180

Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address s…

Fix: 5.3.4 / 6.1.2+
Fix from $1,950 2024-03-21
Webpack CRITICAL 9.8
CVE-2023-28154

Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who control…

Fix: 5.76.0+
Fix from $2,300 2023-03-13
Loader Utils HIGH 7.5
CVE-2022-37603

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the…

Fix: 1.4.2 / 2.0.4+
Fix from $1,950 2022-10-14
Loader Utils HIGH 7.5
CVE-2022-37599

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the…

Fix: 1.4.2 / 2.0.4+
Fix from $1,950 2022-10-11
Webpack Dev Server HIGH 7.5
CVE-2018-14732

An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of reque…

Fix: 3.1.6+
Fix from $1,950 2018-09-21