webpack-dev-middleware vulnerabilities
CVEs whose affected-version data names the webpack-dev-middleware package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
GHSA-p3f5-w63m-mxphHigh· 7.4Duplicate Advisory: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
Duplicate Advisory: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
▾ Twilightwebpack-dev-middleware · webpack-dev-middlewarevia GHSA
CVE-2026-76844High· 7.4webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset
webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normaliz…
▾ Twilightwebpack-dev-middleware · webpack-dev-middlewareEPSS 0.48%via NVD