CVE-2026-14631Disclosure(webpack.js / webpack-dev-server)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch webpack.js webpack-dev-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the host-validation path and crashes the dev server. Impact is limited to availability of the development server, no data disclosure, no code execution. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: keep the dev server bound to localhost (the default) and do not expose it to untrusted networks.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-248

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webpack-dev-server

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
webpack-dev-server

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-03: 3Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-03: 307-03
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-14631 webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Hos… https://www.cve.org/CVERecord?id=CVE-2026-14631 ----- Traducción: CVE-2026-14631 web… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑14631, explaining that unauthenticated, malformed Host header requests cause a crash in webpack‑dev‑server versions 5.2.5 and older.

    0000048
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-14631 webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Hos… https://www.cve.org/CVERecord?id=CVE-2026-14631

    Post summary

    CVE-2026-14631 is a disclosure of a denial‑of‑service issue in webpack‑dev‑server 5.2.5 and earlier; unauthenticated requests with malformed Host headers cause the entire Node.js process to terminate.

    00000822
    57.7K followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in webpack-dev-server@5.2.6 just released! Patches CVE-2026-14631: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-m28w-2pqf-7qgj

    Post summary

    A medium‑severity denial‑of‑service vulnerability (CVE‑2026‑14631) was fixed in webpack‑dev‑server 5.2.6, and a GitHub advisory details the patch.

    00000176
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebpack.jswebpack-dev-server---

Explore more