Junglewise Threat Intelligence

CVE-2026-14631: webpack webpack-dev-server Denial of Service via malformed headers

CVE-2026-14631 · Severity: medium · CVSS 5.3 · Published 2026-07-03

Technologies: webpack-dev-server (npm), Webpack Dev-Server. Vendors: npm, Webpack.

Executive brief

webpack-dev-server is a development tool used by software engineers to preview web applications in real-time. A vulnerability in this tool allows an attacker to crash the development server by sending a specially crafted web request. This results in a denial of service, interrupting the development workflow and requiring a manual restart of the server process.

Technical details

A denial of service vulnerability exists in webpack-dev-server due to improper input validation (CWE-20) and an uncaught exception (CWE-248) in the host-validation path. An unauthenticated remote attacker can trigger a process crash by sending a malformed Host header in a standard HTTP request or a malformed Origin header during a WebSocket upgrade to the /ws endpoint. The vulnerability is exploitable if the dev server is exposed to untrusted networks. The issue is fixed in version 5.2.6 by ensuring malformed headers are treated as invalid rather than throwing an exception.

Affected products

  • webpack webpack-dev-server <= 5.2.5

Timeline

  • 2026-07-03: disclosed: NVD publication date
  • 2026-07-20: advisory: GitHub Advisory published
  • 2026-07-20: patched: Fixed in version 5.2.6

References

Related threats