VDB

CVE-2026-9595

CVE-2026-9595 PUBLISHED CVSS 5.3 MEDIUM

Reported by openjs · Published June 15, 2026

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket). Patches: Fixed in webpack-dev-server@5.2.5. Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.

Risk Scores

CVSS 3.1
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected Products

VendorProductVersions
webpack-dev-serverwebpack-dev-server0, 5.2.5
webpack-dev-serverwebpack-dev-server0, 5.2.5, 0
chainguardkubeflow-katib0, 0, 0
chainguardargo-workflows-3.70, 0, 0
wolfikubeflow-katib0, 0, 0
wolfiargo-workflows-4.00, 0, 0
chainguardargo-workflows-4.00, 0, 0
npmwebpack-dev-server0
chainguardargo-workflows-3.60, 0, 0
wolfiargo-workflows-3.70, 0, 0

Timeline

  • Jun 15, 2026 CVE Published
  • Jun 16, 2026 EPSS Score
  • Jun 16, 2026 Coalition ESS Score
  • Jun 19, 2026 Security Advisory
  • Jul 20, 2026 Distribution Patch
  • Jul 20, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 21, 2026 Distribution Patch
  • Aug 21, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›