Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-m28w-2pqf-7qgj
  • npm/webpack-dev-server
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-f5vj-f2hx-8m93
  • npm/webpack-dev-server
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints yesterday
  • Fix available
  • Severity - 4.7 (Medium)
MAL-2026-10859
  • npm/@gocortexio/npmgremlinbox-typosquat-webpack
Malicious code in @gocortexio/npmgremlinbox-typosquat-webpack (npm) 2 days ago
  • No fix available
MAL-2026-10653
  • npm/webpack-session-cache
Malicious code in webpack-session-cache (npm) 15 Jul
  • No fix available
GHSA-mx8g-39q3-5c79
  • npm/webpack-dev-server
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies 17 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-x6qj-4h56-5rj5
  • npm/@nuxt/rspack-builder
  • npm/@nuxt/webpack-builder
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g) 16 Jun
  • Fix available
  • Severity - 5.9 (Medium)
MAL-2026-5579
  • npm/webpack-cache-cycle
Malicious code in webpack-cache-cycle (npm) 11 Jun
  • No fix available
MAL-2026-5581
  • npm/webpack-patch
Malicious code in webpack-patch (npm) 11 Jun
  • No fix available
MAL-2026-5578
  • npm/webpack-cache-clean
Malicious code in webpack-cache-clean (npm) 11 Jun
  • No fix available
MAL-2026-5580
  • npm/webpack-cache-reset
Malicious code in webpack-cache-reset (npm) 11 Jun
  • No fix available
MAL-2026-5175
  • npm/webpack-json
Malicious code in webpack-json (npm) 03 Jun
  • No fix available
MAL-2026-4352
  • npm/xarc-webpack-cli
Malicious code in xarc-webpack-cli (npm) 25 May
  • No fix available
GHSA-6m52-m754-pw2g
  • npm/@nuxt/rspack-builder
  • npm/@nuxt/webpack-builder
Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99) 19 May
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-79cf-xcqc-c78w
  • npm/webpack-dev-server
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins 18 May
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-rv78-f8rc-xrxh
  • npm/react-server-dom-parcel
  • npm/react-server-dom-turbopack
  • npm/react-server-dom-webpack
Facebook React has a Denial of Service Vulnerability in React Server Components 11 May
  • Fix available
  • Severity - 7.5 (High)
GHSA-479c-33wc-g2pg
  • npm/react-server-dom-parcel
  • npm/react-server-dom-turbopack
  • npm/react-server-dom-webpack
React Server Components have a Denial of Service Vulnerability 10 Apr
  • Fix available
  • Severity - 7.5 (High)