Junglewise Threat Intelligence

CVE-2025-68458: webpack buildHttp allowedUris bypass via URL userinfo

CVE-2025-68458 · Severity: low · CVSS 3.1 · Published 2026-02-05

Technologies: webpack (npm). Vendors: npm, Webpack.

Executive brief

webpack is a popular JavaScript bundler used to package applications for deployment. When the experimental buildHttp feature is enabled with URL allow-lists (allowedUris), an attacker can craft malicious URLs that bypass this security policy using the "@" character, causing the build process to fetch code from unauthorized internal servers. This could allow an attacker to inject malicious code into production bundles or access sensitive internal services during the build phase.

Technical details

The vulnerability exists in webpack's HttpUriPlugin (when experiments.buildHttp is enabled) due to inconsistent URL validation and parsing. The allowedUris allow-list is validated against the raw URI string using simple prefix matching (e.g., startsWith), while the actual HTTP request destination is determined by parsing the URL with the URL constructor, which interprets the authority/host as the component following the "@" character. An attacker can craft URLs like "http://127.0.0.1:9000@127.0.0.1:9100/secret.js" that pass validation against an allow-list containing "http://127.0.0.1:9000" but actually connect to "http://127.0.0.1:9100", enabling server-side request forgery (SSRF) and untrusted code injection. The fetched responses are treated as legitimate module source and bundled into the application. Exploitation requires the buildHttp experimental feature to be enabled and user interaction in the build process. A fix is available in webpack version 5.104.1 and later.

Affected products

  • webpack webpack >=5.49.0 <=5.104.0

Timeline

  • 2026-02-05: disclosed
  • 2026-02-05: patched: Fixed in version 5.104.1

References

Related threats