Webpack.js maintains a modestly represented but prominent build toolchain and development-server ecosystem that is widely integrated into JavaScript development pipelines. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in core products such as Webpack, Webpack Dev Server, and loader utilities, with recurring exposure through dangerous method exposure, ReDoS patterns, server-side request forgery, input validation gaps, and path-traversal weaknesses that reflect the complexity of bundler plugin interfaces and file-system access in development tooling. Defenders should monitor this vendor's releases closely given the breadth of downstream projects that depend on these tools; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webpack.Js over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37601CRITICAL Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 a | Oct 12, 2022 | 9.8 | 32 | NO | NO |
CVE-2023-28154CRITICAL Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted ob | Mar 13, 2023 | 9.8 | 31 | NO | NO |
CVE-2026-14631MEDIUM webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a | Jul 3, 2026 | 5.3 | 29 | NO | NO |
CVE-2026-14620MEDIUM webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changi | Jul 3, 2026 | 4.7 | 27 | NO | NO |
CVE-2026-6402MEDIUM webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. | May 12, 2026 | 6.5 | 27 | NO | NO |
CVE-2018-14732HIGH An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSo | Sep 21, 2018 | 7.5 | 26 | NO | NO |
CVE-2022-37599HIGH A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in inter | Oct 11, 2022 | 7.5 | 25 | NO | NO |
CVE-2024-29180HIGH Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address sufficiently before returning th | Mar 21, 2024 | 7.5 | 23 | NO | NO |
CVE-2026-9595MEDIUM Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the p | Jun 15, 2026 | 4.3 | 22 | NO | NO |
CVE-2022-37603HIGH A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateNam | Oct 14, 2022 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webpack.Js.
Media articles that mention a CVE ID that affects a product developed by Webpack.Js — matched by CVE ID, not by vendor name.