
🔒 New advisory: webpack-dev-server (CVE-2026-9595). A proxy with context / and ws: true intercepts the HMR WebSocket, leaking cookies to the backend. ✅ Patched in 5.2.5 https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79
Post summary
A new advisory for webpack‑dev‑server CVE‑2026‑9595 reveals a cookie leak via the HMR WebSocket with a proxy setting, and a patch is available in version 5.2.5.

