Back

HIGH

webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies

Published Jun 15, 2026

Description

Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket).

Patches: Fixed in webpack-dev-server@5.2.5.

Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, users should avoid configuring `webpack-dev-server` with a broad proxy context (e.g., `/`) when WebSocket forwarding (`ws: true`) is enabled. Instead, define specific paths for the proxy context. Alternatively, disable WebSocket forwarding by omitting `ws: true` from the proxy entry if WebSocket functionality is not required for the proxy target. This configuration change may require restarting the `webpack-dev-server` instance to take effect.

Metrics

Weaknesses (2)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner openjs
Published Jun 15, 2026
Updated Jun 15, 2026
Reserved May 26, 2026
CISA Vulnrichment
Updated Jun 15, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 15, 2026
GHSA-MX8G-39Q3-5C79