Webpack Dev Server
Vendor:
First CVE: Sep 21, 2018 · Active for 7 years
7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Webpack Dev Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 21, 2018
7 years ago
Most Recent CVE
Jul 3, 2026
21 days ago
CVE Severity & Scoring
Webpack Dev Server7 CVEs
86%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-14631MEDIUM webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a | Jul 3, 2026 | 5.3 | 29 | NO | NO |
CVE-2026-14620MEDIUM webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changi | Jul 3, 2026 | 4.7 | 27 | NO | NO |
CVE-2026-6402MEDIUM webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. | May 12, 2026 | 6.5 | 27 | NO | NO |
CVE-2018-14732HIGH An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSo | Sep 21, 2018 | 7.5 | 26 | NO | NO |
CVE-2026-9595MEDIUM Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the p | Jun 15, 2026 | 4.3 | 22 | NO | NO |
CVE-2025-30359MEDIUM webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen w | Jun 3, 2025 | 5.9 | 19 | NO | NO |
CVE-2025-30360MEDIUM webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen w | Jun 3, 2025 | 6.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Webpack Dev Server
Top CWEs
Versions
No cataloged versions.