webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
Published Jun 15, 2026
7.1
HIGHCVSS 3.1
EPSS 0.23%
Description
Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket).
Patches: Fixed in webpack-dev-server@5.2.5.
Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.
Affected products
-
- Version 0StatusaffectedConstraints<5.2.5
- Version 5.2.5StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Webpack-Dev-Server | Webpack-Dev-Server | unaffected |
|
- < 5.2.5
No data.
Red Hat AMQ Broker 7.13.6
webpack-dev-server
Fixed · RHSA-2026:66545
Red Hat AMQ Broker 7.14.1
webpack-dev-server
Fixed · RHSA-2026:66488
Red Hat Ansible Automation Platform 2.1
ansible-automation-platform/automation-portal:1787047114
Fixed · RHSA-2026:56338
Red Hat Ansible Automation Platform 2.2
ansible-automation-platform/automation-portal:1787047188
Fixed · RHSA-2026:56357
Red Hat Ansible Automation Platform 2.5
ansible-automation-platform-25/lightspeed-rhel8:1785430174
Fixed · RHSA-2026:50357
Red Hat Ansible Automation Platform 2.6
ansible-automation-platform-26/gateway-rhel9:1787219751
Fixed · RHSA-2026:59155
Red Hat Ansible Automation Platform 2.6
ansible-automation-platform-26/lightspeed-rhel9:1785775360
Fixed · RHSA-2026:50479
Red Hat Ansible Automation Platform 2.7
ansible-automation-platform-27/gateway-rhel9:1787218409
Fixed · RHSA-2026:59153
Red Hat Data Grid 8.6.2
webpack-dev-server
Fixed · RHSA-2026:41951
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1786634825
Fixed · RHSA-2026:54760
Red Hat Enterprise Linux 10
rh-podman-desktop-0:1.1.2-1.el10_2
Fixed · RHSA-2026:57590
Red Hat Migration Toolkit 1.8
rhmtc/openshift-migration-ui-rhel8:1783690532
Fixed · RHSA-2026:41928
Red Hat OpenShift Container Platform 4.19
openshift4/ose-console-rhel9:1787089523
Fixed · RHSA-2026:57408
Red Hat OpenShift Container Platform 4.20
openshift4/ose-console-rhel9:1783602326
Fixed · RHSA-2026:37628
Red Hat OpenShift Container Platform 4.21
openshift4/ose-console-rhel9:1783502338
Fixed · RHSA-2026:37186
Red Hat OpenShift Container Platform 4.22
openshift4/ose-agent-installer-ui-rhel9:1785910896
Fixed · RHSA-2026:51038
Red Hat OpenShift Container Platform 4.22
openshift4/ose-console-rhel9:1782913621
Fixed · RHSA-2026:34794
Cryostat 4
cryostat-openshift-console-plugin-npm
Not affected
Cryostat 4
webpack-dev-server
Not affected
Gatekeeper 3
gatekeeper/gatekeeper-rhel9
Not affected
Node HealthCheck Operator
workload-availability/node-healthcheck-must-gather-rhel9
Affected
Node HealthCheck Operator
workload-availability/node-healthcheck-operator-bundle
Affected
Node HealthCheck Operator
workload-availability/node-healthcheck-rhel9-operator
Affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-419-rhel9
Affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9
Affected
OpenShift Lightspeed
openshift-lightspeed/lightspeed-console-plugin-rhel9
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-pf5-rhel9
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel8
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-console-plugin-rhel9
Affected
OpenShift Pipelines
openshift-pipelines/pipelines-hub-ui-rhel8
Will not fix
OpenShift Pipelines
openshift-pipelines/pipelines-hub-ui-rhel9
Will not fix
OpenShift Service Mesh 2
openshift-service-mesh/kiali-ossmc-rhel8
Not affected
OpenShift Service Mesh 2
openshift-service-mesh/kiali-rhel8
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-operator-bundle
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-ossmc-rhel9
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9
Not affected
OpenShift Service Mesh 3
openshift-service-mesh/kiali-rhel9-operator
Not affected
Red Hat Ansible Automation Platform 2
automation-eda-controller
Will not fix
Red Hat Build of Podman Desktop
rh-podman-desktop.git
Will not fix
Red Hat Connectivity Link 1
rhcl-1/rhcl-console-plugin-rhel9
Affected
Red Hat Developer Hub
rhdh/rhdh-hub-rhel9
Not affected
Red Hat Enterprise Linux 10
grafana
Not affected
Red Hat Enterprise Linux 10
js-d3-flame-graph
Not affected
Red Hat Enterprise Linux 10
pcs
Not affected
Red Hat Enterprise Linux 8
dotnet5.0-build-reference-packages
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
js-d3-flame-graph
Not affected
Red Hat Enterprise Linux 8
pcs
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Enterprise Linux 9
js-d3-flame-graph
Not affected
Red Hat Enterprise Linux 9
pcs
Not affected
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-cuda-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-gaudi-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/bootc-rocm-rhel9
Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3
rhelai3/disk-image-cuda-rhel9
Will not fix
Red Hat Fuse 7
webpack-dev-server
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-mlflow-rhel9
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ose-console
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/kubevirt-console-plugin
Not affected
Red Hat OpenShift Virtualization 4
container-native-virtualization/kubevirt-console-plugin-rhel9
Not affected
Red Hat Quay 3
quay/quay-rhel8
Will not fix
Red Hat build of Apache Camel - HawtIO 4
webpack-dev-server
Affected
Red Hat build of Apache Camel for Spring Boot 4
webpack-dev-server
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Broker 7.13.6 | webpack-dev-server | Fixed | RHSA-2026:66545 |
| Red Hat AMQ Broker 7.14.1 | webpack-dev-server | Fixed | RHSA-2026:66488 |
| Red Hat Ansible Automation Platform 2.1 | ansible-automation-platform/automation-portal:1787047114 | Fixed | RHSA-2026:56338 |
| Red Hat Ansible Automation Platform 2.2 | ansible-automation-platform/automation-portal:1787047188 | Fixed | RHSA-2026:56357 |
| Red Hat Ansible Automation Platform 2.5 | ansible-automation-platform-25/lightspeed-rhel8:1785430174 | Fixed | RHSA-2026:50357 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/gateway-rhel9:1787219751 | Fixed | RHSA-2026:59155 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/lightspeed-rhel9:1785775360 | Fixed | RHSA-2026:50479 |
| Red Hat Ansible Automation Platform 2.7 | ansible-automation-platform-27/gateway-rhel9:1787218409 | Fixed | RHSA-2026:59153 |
| Red Hat Data Grid 8.6.2 | webpack-dev-server | Fixed | RHSA-2026:41951 |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1786634825 | Fixed | RHSA-2026:54760 |
| Red Hat Enterprise Linux 10 | rh-podman-desktop-0:1.1.2-1.el10_2 | Fixed | RHSA-2026:57590 |
| Red Hat Migration Toolkit 1.8 | rhmtc/openshift-migration-ui-rhel8:1783690532 | Fixed | RHSA-2026:41928 |
| Red Hat OpenShift Container Platform 4.19 | openshift4/ose-console-rhel9:1787089523 | Fixed | RHSA-2026:57408 |
| Red Hat OpenShift Container Platform 4.20 | openshift4/ose-console-rhel9:1783602326 | Fixed | RHSA-2026:37628 |
| Red Hat OpenShift Container Platform 4.21 | openshift4/ose-console-rhel9:1783502338 | Fixed | RHSA-2026:37186 |
| Red Hat OpenShift Container Platform 4.22 | openshift4/ose-agent-installer-ui-rhel9:1785910896 | Fixed | RHSA-2026:51038 |
| Red Hat OpenShift Container Platform 4.22 | openshift4/ose-console-rhel9:1782913621 | Fixed | RHSA-2026:34794 |
| Cryostat 4 | cryostat-openshift-console-plugin-npm | Not affected | n/a |
| Cryostat 4 | webpack-dev-server | Not affected | n/a |
| Gatekeeper 3 | gatekeeper/gatekeeper-rhel9 | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-must-gather-rhel9 | Affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-operator-bundle | Affected | n/a |
| Node HealthCheck Operator | workload-availability/node-healthcheck-rhel9-operator | Affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-419-rhel9 | Affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-pf5-rhel9 | Affected | n/a |
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-console-plugin-rhel9 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-pf5-rhel9 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel8 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-console-plugin-rhel9 | Affected | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel8 | Will not fix | n/a |
| OpenShift Pipelines | openshift-pipelines/pipelines-hub-ui-rhel9 | Will not fix | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-ossmc-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2 | openshift-service-mesh/kiali-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-operator-bundle | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-ossmc-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9 | Not affected | n/a |
| OpenShift Service Mesh 3 | openshift-service-mesh/kiali-rhel9-operator | Not affected | n/a |
| Red Hat Ansible Automation Platform 2 | automation-eda-controller | Will not fix | n/a |
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Will not fix | n/a |
| Red Hat Connectivity Link 1 | rhcl-1/rhcl-console-plugin-rhel9 | Affected | n/a |
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 10 | js-d3-flame-graph | Not affected | n/a |
| Red Hat Enterprise Linux 10 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet5.0-build-reference-packages | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | js-d3-flame-graph | Not affected | n/a |
| Red Hat Enterprise Linux 8 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | js-d3-flame-graph | Not affected | n/a |
| Red Hat Enterprise Linux 9 | pcs | Not affected | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Will not fix | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/disk-image-cuda-rhel9 | Will not fix | n/a |
| Red Hat Fuse 7 | webpack-dev-server | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-mlflow-rhel9 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ose-console | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/kubevirt-console-plugin | Not affected | n/a |
| Red Hat OpenShift Virtualization 4 | container-native-virtualization/kubevirt-console-plugin-rhel9 | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Will not fix | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | webpack-dev-server | Affected | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | webpack-dev-server | Not affected | n/a |
webpack-dev-server
npm
Introduced 0 Fixed 5.2.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | webpack-dev-server | 0 | 5.2.5 |
Remediation
Red Hat mitigation
To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
2 other sources (GHSA, Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jun 15, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Jun-Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.23% (0.00233) | 12.86th | v5 (v2026.06.15) |
| Jun 16, 2026 | 0.19% (0.00195) | 9.33th | v5 (v2026.06.15) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-9595 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2488934 Issue Tracking
- https://cna.openjsf.org/security-advisories.html Vendor Advisory
- https://github.com/advisories/GHSA-mx8g-39q3-5c79 Advisory
- https://github.com/facebook/create-react-app/pull/7444 Issue TrackingPatch
- https://github.com/vuejs/vue-cli/commit/72ba7505aff2a8314e82aa5082379a77504a1fcb Patch
- https://github.com/webpack/webpack-dev-server/pull/4316 Issue TrackingPatch
- https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79 MitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-9595
- https://www.cve.org/CVERecord?id=CVE-2026-9595
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-9595 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2488934 | Issue Tracking | |
| https://cna.openjsf.org/security-advisories.html | Vendor Advisory | |
| https://github.com/advisories/GHSA-mx8g-39q3-5c79 | Advisory | |
| https://github.com/facebook/create-react-app/pull/7444 | Issue TrackingPatch | |
| https://github.com/vuejs/vue-cli/commit/72ba7505aff2a8314e82aa5082379a77504a1fcb | Patch | |
| https://github.com/webpack/webpack-dev-server/pull/4316 | Issue TrackingPatch | |
| https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79 | MitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-9595 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-9595 |
Change history (0)
No recorded changes yet.