{"id":"CVE-2026-14631","aliases":["GHSA-m28w-2pqf-7qgj"],"url":"https://o3.security/vulnerability/CVE-2026-14631","summary":"webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header","details":"webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the host-validation path and crashes the dev server. Impact is limited to availability of the development server, no data disclosure, no code execution. Patches: upgrade to webpack-dev-server 5.2.6. Workarounds: keep the dev server bound to localhost (the default) and do not expose it to untrusted networks.","published":"2026-07-03T17:23:41.451Z","modified":"2026-09-04T15:55:53.205673180Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":{"score":0.00517,"percentile":0.42116,"asOf":"2026-09-06"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"webpack-dev-server","fixedVersion":"5.2.6"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/14xxx/CVE-2026-14631.json"},{"type":"ADVISORY","url":"https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-m28w-2pqf-7qgj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14631"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-04T15:55:53.205673180Z"}}