VYPR
Medium severity5.3NVD Advisory· Published Jun 15, 2026· Updated Jun 16, 2026

CVE-2026-9595

CVE-2026-9595

Description

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket).

Patches: Fixed in webpack-dev-server@5.2.5.

Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
webpack-dev-servernpm
< 5.2.55.2.5

Affected products

8

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.