7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether webpack-dev-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-9595
webpack-dev-server vulnerable to HMR WebSocket interception via permissive user proxies
MEDIUM 5.3
CVE-2026-14631
webpack-dev-server vulnerable to denial of service via a malformed Host or Origin header
MEDIUM 4.7
CVE-2026-14620
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints
MEDIUM 5.3
CVE-2026-6402
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
MEDIUM 6.5
CVE-2025-30360
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
MEDIUM 5.3
CVE-2025-30359
webpack-dev-server users' source code may be stolen when they access a malicious web site
HIGH 7.5
CVE-2018-14732
Missing Origin Validation in webpack-dev-server
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes