{"id":"CVE-2026-9595","title":"webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies","summary":"webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies","severity":"medium","cvss":5.3,"cwe":["CWE-346","CWE-441"],"vendor":"webpack-dev-server","product":"webpack-dev-server","ecosystem":"npm","affected":["webpack-dev-server < 5.2.5"],"patched":["webpack-dev-server 5.2.5"],"published":"2026-06-17","updated":"2026-06-17","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-mx8g-39q3-5c79","references":[{"url":"https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9595"},{"url":"https://github.com/facebook/create-react-app/pull/7444"},{"url":"https://github.com/webpack/webpack-dev-server/pull/4316"},{"url":"https://github.com/vuejs/vue-cli/commit/72ba7505aff2a8314e82aa5082379a77504a1fcb"},{"url":"https://cna.openjsf.org/security-advisories.html"},{"url":"https://github.com/advisories/GHSA-mx8g-39q3-5c79"}],"tags":["ghsa","npm"],"epss":0.00163,"epssPercentile":0.05906,"ingestedAt":"2026-06-29T14:31:47.219Z","slug":"CVE-2026-9595","body":"## Overview\n\n### Impact\n\nWhen a user-configured proxy on `webpack-dev-server` has a broad context (e.g. `/`) and `ws: true`, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and `Origin` header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket).\n\n### Patches\n\nFixed in `webpack-dev-server` 5.2.5.\n\n### Workarounds\n\nScope user-defined proxy `context` to specific paths instead of `/`, or omit `ws: true` from the proxy entry when WebSocket forwarding is not required.\n\n## Affected packages\n\n- `webpack-dev-server < 5.2.5`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `webpack-dev-server 5.2.5`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}