Skip to content
Noroxi

webpack.js records

15 published records for vendor webpack.js.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

15 records
  • Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js.

    CriticalCVSS 9.8No exploitEPSS 3%

    webpack.js · loader-utilsOct 12, 2022

  • Webpack 5 before 5.76.0 does not avoid cross-realm object access.

    CriticalCVSS 9.8No exploitEPSS 1%

    webpack.js · webpackMar 12, 2023

  • An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6.

    HighCVSS 7.5No exploitEPSS 3%

    webpack.js · webpack-dev-serverSep 21, 2018

  • A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.

    HighCVSS 7.5No exploitEPSS 2%

    webpack.js · loader-utilsOct 11, 2022

  • A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.

    HighCVSS 7.5No exploitEPSS 2%

    webpack.js · loader-utilsOct 14, 2022

  • webpack-dev-middleware Path Traversal vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    webpack.js · webpack-dev-middlewareMar 21, 2024

  • CVE-2026-6402
    26Monitor

    webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins

    MediumCVSS 6.5No exploitEPSS 0%

    webpack.js · webpack-dev-serverMay 12, 2026

  • webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser

    MediumCVSS 6.5No exploitEPSS 0%

    webpack.js · webpack-dev-serverJun 3, 2025

  • DOM Clobbering Gadget found in Webpack's AutoPublicPathRuntimeModule that leads to Cross-site Scripting (XSS)

    MediumCVSS 6.1Proof of conceptEPSS 1%

    webpack.js · webpackAug 27, 2024

  • webpack-dev-server users' source code may be stolen when they access a malicious web site

    MediumCVSS 5.9No exploitEPSS 1%

    webpack.js · webpack-dev-serverJun 3, 2025

  • webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header

    MediumCVSS 5.3No exploitEPSS 1%

    webpack.js · webpack-dev-serverJul 3, 2026

  • webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints

    MediumCVSS 4.7Proof of conceptEPSS 1%

    webpack.js · webpack-dev-serverJul 3, 2026

  • CVE-2026-9595
    17Monitor

    webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

    MediumCVSS 4.3No exploitEPSS 0%

    webpack.js · webpack-dev-serverJun 15, 2026

  • webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior

    LowCVSS 3.7No exploitEPSS 0%

    webpack.js · webpackFeb 5, 2026

  • webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects

    LowCVSS 3.7No exploitEPSS 0%

    webpack.js · webpackFeb 5, 2026