VYPR

Webpack Dev Middleware

by Webpack

Source repositories

CVEs (2)

  • CVE-2026-76844HigAug 24, 2026
    risk 0.48cvss 7.4epss 0.00

    webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normalize(`./${pathname}`), only matches ".." that…

  • CVE-2024-29180HigMar 21, 2024
    risk 0.41cvss 7.4epss 0.01

    Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the developer's machine. The middleware can…