{"id":"UBUNTU-CVE-2026-9595","details":"Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket). Patches: Fixed in webpack-dev-server@5.2.5. Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.","modified":"2026-06-24T08:58:46Z","published":"2026-06-15T16:16:00Z","upstream":["CVE-2026-9595"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-9595"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-9595"},{"type":"REPORT","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"REPORT","url":"https://github.com/facebook/create-react-app/pull/7444"},{"type":"REPORT","url":"https://github.com/vuejs/vue-cli/commit/72ba7505aff2a8314e82aa5082379a77504a1fcb"},{"type":"REPORT","url":"https://github.com/webpack/webpack-dev-server/pull/4316"},{"type":"REPORT","url":"https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-mx8g-39q3-5c79"}],"affected":[{"package":{"name":"node-webpack","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.5.6-1build3","3.5.6-1build4","3.5.6-2"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"3.5.6-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.7.0-3","4.30.0-7","4.30.0-9"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"4.30.0-9"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"vue.js","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/vue.js?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5.17+dfsg-4"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-vue","binary_version":"2.5.17+dfsg-4"},{"binary_name":"node-vue","binary_version":"2.5.17+dfsg-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.43.0-6build4","4.43.0-7"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"4.43.0-7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"vue.js","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/vue.js?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.12+dfsg-3","2.6.14+dfsg-1","2.6.14+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-vue","binary_version":"2.6.14+dfsg-2"},{"binary_name":"node-vue","binary_version":"2.6.14+dfsg-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.76.1+dfsg1+~cs17.16.16-1"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"5.76.1+dfsg1+~cs17.16.16-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"vue.js","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/vue.js?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.14+dfsg1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.6.14+dfsg1-1","binary_name":"libjs-vue"},{"binary_version":"2.6.14+dfsg1-1","binary_name":"node-vue"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.97.1+dfsg1+~cs11.18.27-2","5.97.1+dfsg1+~cs11.18.27-3"],"ecosystem_specific":{"binaries":[{"binary_name":"webpack","binary_version":"5.97.1+dfsg1+~cs11.18.27-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"vue.js","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/vue.js?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.14+dfsg1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-vue","binary_version":"2.6.14+dfsg1-1"},{"binary_version":"2.6.14+dfsg1-1","binary_name":"node-vue"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"node-webpack","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/node-webpack?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.97.1+dfsg1+~cs11.18.27-3","5.97.1+dfsg1+~cs11.18.27-4","5.105.4+dfsg1+~cs15.13.23-2"],"ecosystem_specific":{"binaries":[{"binary_version":"5.105.4+dfsg1+~cs15.13.23-2","binary_name":"webpack"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}},{"package":{"name":"vue.js","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/vue.js?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.14+dfsg1-1","2.6.14+dfsg1-1build1","2.6.14+dfsg1-2","2.6.14+dfsg1-3"],"ecosystem_specific":{"binaries":[{"binary_name":"libjs-vue","binary_version":"2.6.14+dfsg1-3"},{"binary_name":"node-vue","binary_version":"2.6.14+dfsg1-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-9595.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]}