webpack-dev-middleware has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 7.4 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
Weakness classes
Products
- webpack-dev-middleware 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
GHSA-p3f5-w63m-mxphHigh· 7.4Duplicate Advisory: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath41CVE-2026-76844High· 7.4webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset41
webpack-dev-middleware vulnerabilities
CVEs affecting webpack-dev-middleware, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
GHSA-p3f5-w63m-mxphHigh· 7.4Duplicate Advisory: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
Duplicate Advisory: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
▾ Twilightwebpack-dev-middleware · webpack-dev-middlewarevia GHSA
CVE-2026-76844High· 7.4webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset
webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normaliz…
▾ Twilightwebpack-dev-middleware · webpack-dev-middlewareEPSS 0.48%via NVD