{"id":"UBUNTU-CVE-2025-68157","details":"Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.","modified":"2026-05-20T16:23:42.540672980Z","published":"2026-02-05T23:15:00Z","upstream":["CVE-2025-68157"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-68157"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-68157"},{"type":"REPORT","url":"https://github.com/webpack/webpack/security/advisories/GHSA-38r7-794h-5758"}],"affected":[{"package":{"name":"node-webpack","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.5.6-1build3","3.5.6-1build4","3.5.6-2"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"3.5.6-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68157.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.7.0-3","4.30.0-7","4.30.0-9"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"4.30.0-9"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68157.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.43.0-6build4","4.43.0-7"],"ecosystem_specific":{"binaries":[{"binary_version":"4.43.0-7","binary_name":"webpack"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68157.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.76.1+dfsg1+~cs17.16.16-1"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"5.76.1+dfsg1+~cs17.16.16-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68157.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.97.1+dfsg1+~cs11.18.27-2","5.97.1+dfsg1+~cs11.18.27-3"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"5.97.1+dfsg1+~cs11.18.27-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68157.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.97.1+dfsg1+~cs11.18.27-3","5.97.1+dfsg1+~cs11.18.27-4","5.105.4+dfsg1+~cs15.13.23-2"],"ecosystem_specific":{"binaries":[{"binary_version":"5.105.4+dfsg1+~cs15.13.23-2","binary_name":"webpack"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-68157.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}