
CVE-2025-68458 Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed … https://www.cve.org/CVERecord?id=CVE-2025-68458
Post summary
The entry announces a webpack vulnerability affecting versions 5.49.0–5.104.0 that allows bypassing the HTTP(S) resolver when experiments.buildHttp is enabled, with no PoC, exploit, patch, or active exploitation mentioned.

