---
id: CVE-2026-9595
title: >-
  webpack-dev-server vulnerable to HMR WebSocket interception via permissive
  user proxies
summary: >-
  webpack-dev-server vulnerable to HMR WebSocket interception via permissive
  user proxies
severity: medium
cvss: 5.3
cwe:
  - CWE-346
  - CWE-441
vendor: webpack-dev-server
product: webpack-dev-server
ecosystem: npm
affected:
  - webpack-dev-server < 5.2.5
patched:
  - webpack-dev-server 5.2.5
published: '2026-06-17'
updated: '2026-06-17'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-mx8g-39q3-5c79'
references:
  - url: >-
      https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-9595'
  - url: 'https://github.com/facebook/create-react-app/pull/7444'
  - url: 'https://github.com/webpack/webpack-dev-server/pull/4316'
  - url: >-
      https://github.com/vuejs/vue-cli/commit/72ba7505aff2a8314e82aa5082379a77504a1fcb
  - url: 'https://cna.openjsf.org/security-advisories.html'
  - url: 'https://github.com/advisories/GHSA-mx8g-39q3-5c79'
tags:
  - ghsa
  - npm
epss: 0.00163
epssPercentile: 0.05916
ingestedAt: '2026-06-29T14:31:47.219Z'
---

## Overview

### Impact

When a user-configured proxy on `webpack-dev-server` has a broad context (e.g. `/`) and `ws: true`, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and `Origin` header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket).

### Patches

Fixed in `webpack-dev-server` 5.2.5.

### Workarounds

Scope user-defined proxy `context` to specific paths instead of `/`, or omit `ws: true` from the proxy entry when WebSocket forwarding is not required.

## Affected packages

- `webpack-dev-server < 5.2.5`

## Remediation

Upgrade to a patched release:

- `webpack-dev-server 5.2.5`
