Improper Input Validation Affecting webpack-dev-server package, versions <5.2.6


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.41% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Input Validation vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-WEBPACKDEVSERVER-17812743
  • published4 Jul 2026
  • disclosed3 Jul 2026
  • creditStr1ckl4nd, Zyy0530

Introduced: 3 Jul 2026

NewCVE-2026-14631  (opens in a new tab)
CWE-20  (opens in a new tab)

How to fix?

Upgrade webpack-dev-server to version 5.2.6 or higher.

Overview

webpack-dev-server is an Uses webpack with a development server that provides live reloading. It should be used for development only.

Affected versions of this package are vulnerable to Improper Input Validation through the host-validation process. An attacker can cause the server to terminate unexpectedly by sending a malformed Host or Origin header in an HTTP request or WebSocket upgrade.

CVSS Base Scores

version 4.0
version 3.1