Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-13050
  • npm/boxy-global-modules-webpack-plugin
Malicious code in boxy-global-modules-webpack-plugin (npm) 05 Aug
  • No fix available
MAL-2026-13097
  • npm/boxy-webpack-test-utils
Malicious code in boxy-webpack-test-utils (npm) 05 Aug
  • No fix available
MAL-2026-13099
  • npm/boxy-wrapper-webpack-plugin
Malicious code in boxy-wrapper-webpack-plugin (npm) 05 Aug
  • No fix available
MAL-2026-12441
  • npm/sme-scripts-shared-library-webpack-plugin
Malicious code in sme-scripts-shared-library-webpack-plugin (npm) 05 Aug
  • No fix available
MAL-2026-12072
  • npm/specials-obid-webpack
Malicious code in specials-obid-webpack (npm) 05 Aug
  • No fix available
MAL-2026-11780
  • npm/@ornikar/webpack-config
Malicious code in @ornikar/webpack-config (npm) 04 Aug
  • No fix available
GHSA-wx67-qw84-cm4g
  • npm/react-server-dom-parcel
  • npm/react-server-dom-turbopack
  • npm/react-server-dom-webpack
react-server-dom: Denial of Service in Server Functions 24 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-m28w-2pqf-7qgj
  • npm/webpack-dev-server
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-f5vj-f2hx-8m93
  • npm/webpack-dev-server
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints 20 Jul
  • Fix available
  • Severity - 4.7 (Medium)
MAL-2026-10859
  • npm/@gocortexio/npmgremlinbox-typosquat-webpack
Malicious code in @gocortexio/npmgremlinbox-typosquat-webpack (npm) 20 Jul
  • No fix available
MAL-2026-10653
  • npm/webpack-session-cache
Malicious code in webpack-session-cache (npm) 15 Jul
  • No fix available
GHSA-mx8g-39q3-5c79
  • npm/webpack-dev-server
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies 17 Jun
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-x6qj-4h56-5rj5
  • npm/@nuxt/rspack-builder
  • npm/@nuxt/webpack-builder
@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g) 16 Jun
  • Fix available
  • Severity - 5.9 (Medium)
MAL-2026-5579
  • npm/webpack-cache-cycle
Malicious code in webpack-cache-cycle (npm) 11 Jun
  • No fix available
MAL-2026-5581
  • npm/webpack-patch
Malicious code in webpack-patch (npm) 11 Jun
  • No fix available
MAL-2026-5578
  • npm/webpack-cache-clean
Malicious code in webpack-cache-clean (npm) 11 Jun
  • No fix available