CVE-2026-9595Patch(webpack.js / webpack-dev-server)

LOWCVSS 4.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch webpack.js webpack-dev-server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket). Patches: Fixed in [email protected]. Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-441

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • webpack-dev-server

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
webpack-dev-server

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-15: 2Patch / Workaround · 2026-06-15: 2Technical Details · 2026-06-15: 206-15
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Sebastian Beltran@bjohansebas
    Patch

    🔒 New advisory: webpack-dev-server (CVE-2026-9595). A proxy with context / and ws: true intercepts the HMR WebSocket, leaking cookies to the backend. ✅ Patched in 5.2.5 https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79

    Post summary

    A new advisory for webpack‑dev‑server CVE‑2026‑9595 reveals a cookie leak via the HMR WebSocket with a proxy setting, and a patch is available in version 5.2.5.

    01060684
    163 followersView on X
  • Ulises Gascón@kom_256
    Patch

    🚨 Medium-severity security fix in webpack-dev-server@5.2.5 just released! Patches CVE-2026-9595. webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies. https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79

    Post summary

    A security fix has been released for CVE-2026-9595, addressing HMR WebSocket interception in webpack-dev-server and providing a patch.

    00010138
    5.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwebpack.jswebpack-dev-server---

Explore more