Multiple security vulnerabilities have been identified in webpack-dev-server, a package that allows developers to serve their applications locally. The overall risk/impact is moderate, with two separate vulnerabilities affecting the component's internal developer endpoints and Host or Origin headers. Affected version range is not explicitly stated.
CVE-2026-14620: webpack-dev-server is vulnerable to cross-site request forgery via internal developer endpoints, allowing an attacker to exploit this vulnerability by manipulating user input. An attacker with medium skill level can exploit this vulnerability.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in webpack-dev-server, a package that allows developers to serve their applications locally. The overall risk/impact is moderate, with two separate vulnerabilities affecting the component's internal developer endpoints and Host or Origin headers. Affected version range is not explicitly stated.
CVE-2026-14620: webpack-dev-server is vulnerable to cross-site request forgery via internal developer endpoints, allowing an attacker to exploit this vulnerability by manipulating user input. An attacker with medium skill level can exploit this vulnerability.[emaillocker id="1283"]
CVE-2026-14631: webpack-dev-server is vulnerable to denial of service via a malformed Host or Origin header, which can cause the application to crash. An attacker with low skill level can exploit this vulnerability.
These vulnerabilities collectively present a moderate risk to developers using webpack-dev-server, particularly those who expose their internal developer endpoints or use custom Host or Origin headers. Administrators should review their exposure and apply updates as necessary.
We recommend you to update webpack-dev-server to the 5.2.6 version.
The following reports contain further technical details:
[/emaillocker]