GHSA-m28w-2pqf-7qgj

    Dashboard / Vulnerabilities / GHSA-m28w-2pqf-7qgj

    GHSA-m28w-2pqf-7qgj

    Published: 20 Jul 2026Last Modified: 10 Sept 2026

    Summary: webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header

    Details: ### Impact An unauthenticated peer that can reach the `webpack-dev-server` process can terminate it by sending either a normal HTTP request with a malformed `Host` header, or a WebSocket upgrade to the default `/ws` endpoint with a malformed `Origin` header. The malformed header triggers an uncaught exception in the host-validation path and crashes the dev server process. ### Patches Fixed in `webpack-dev-server` 5.2.6 by treating malformed `Host` and `Origin` header values as invalid rather than throwing (see [PR #5699](https://github.com/webpack/webpack-dev-server/pull/5699)). ### Workarounds Keep the dev server bound to `localhost` (the default) and do not expose it to untrusted networks.

    Affected packages

    Package

    Name: webpack-dev-server

    Purl: pkg:npm/webpack-dev-server

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -5.2.6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-m28w-2pqf-7qgj | CVE-DB