webpack-dev-middleware
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting webpack-dev-middlewarepage 1 of 1
- CVE-2024-29180HIGHCVSS 7.4EG 7.4✓ Fixed in 5.3.42024-03-21
Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the deve…
- CVE-2026-76844HIGHCVSS 7.4EG 7.4✓ Fixed in 7.1.02026-08-24
webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normalize(…
Check whether webpack-dev-middleware is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for webpack-dev-middleware CVEs against the assets you own.
Start Free Scan →