Threat Advisory

webpack-dev-server Vulnerable to Cross-Site Request Forgery

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in webpack-dev-server, a package that allows developers to serve their applications locally. The overall risk/impact is moderate, with two separate vulnerabilities affecting the component's internal developer endpoints and Host or Origin headers. Affected version range is not explicitly stated.

CVE-2026-14620: webpack-dev-server is vulnerable to cross-site request forgery via internal developer endpoints, allowing an attacker to exploit this vulnerability by manipulating user input. An attacker with medium skill level can exploit this vulnerability.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in webpack-dev-server, a package that allows developers to serve their applications locally. The overall risk/impact is moderate, with two separate vulnerabilities affecting the component's internal developer endpoints and Host or Origin headers. Affected version range is not explicitly stated.

CVE-2026-14620: webpack-dev-server is vulnerable to cross-site request forgery via internal developer endpoints, allowing an attacker to exploit this vulnerability by manipulating user input. An attacker with medium skill level can exploit this vulnerability.[emaillocker id="1283"]

CVE-2026-14631: webpack-dev-server is vulnerable to denial of service via a malformed Host or Origin header, which can cause the application to crash. An attacker with low skill level can exploit this vulnerability.

These vulnerabilities collectively present a moderate risk to developers using webpack-dev-server, particularly those who expose their internal developer endpoints or use custom Host or Origin headers. Administrators should review their exposure and apply updates as necessary.

RECOMMENDATION:

We recommend you to update webpack-dev-server to the 5.2.6 version.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu