CVE-2026-9595
Description
Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket).
Patches: Fixed in webpack-dev-server@5.2.5.
Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
webpack-dev-servernpm | < 5.2.5 | 5.2.5 |
Affected products
8(expand)+ 2 more
- (no CPE)
- cpe:2.3:a:webpack.js:webpack-dev-server:*:*:*:*:*:*:*:*range: <5.2.5
- (no CPE)range: <5.2.5
- osv-coords5 versionspkg:apk/chainguard/argo-workflows-ui-3.7pkg:apk/chainguard/argo-workflows-ui-4.0pkg:apk/wolfi/argo-workflows-ui-3.7pkg:apk/wolfi/argo-workflows-ui-4.0pkg:npm/webpack-dev-server
< 3.7.15-r1+ 4 more
- (no CPE)range: < 3.7.15-r1
- (no CPE)range: < 4.0.6-r1
- (no CPE)range: < 3.7.15-r1
- (no CPE)range: < 4.0.6-r1
- (no CPE)range: < 5.2.5
Patches
Vulnerability mechanics
References
7- github.com/facebook/create-react-app/pull/7444nvdIssue TrackingPatchWEB
- github.com/vuejs/vue-cli/commit/72ba7505aff2a8314e82aa5082379a77504a1fcbnvdPatchWEB
- github.com/webpack/webpack-dev-server/pull/4316nvdIssue TrackingPatchWEB
- cna.openjsf.org/security-advisories.htmlnvdVendor AdvisoryWEB
- github.com/advisories/GHSA-mx8g-39q3-5c79ghsaADVISORY
- github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79nvdMitigationVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-9595ghsaADVISORY
News mentions
0No linked articles in our index yet.