Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 32 respecto a la semana anterior
Críticas / altas1474▲ 364 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.59% | — | Webpack.js Webpack-dev-middlewareAI | 24/8/2026 | 1/10/2026 | zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_write() returns without resetting strm.next_in, leaving it pointed at the caller's buffer. A later gz* write call then derives a position from the stale pointer and writes past a heap allocation; any write() failure… | |
| Pendiente de análisis | Alta (7.5) | 0.60% | — | Facebook React-server-dom-webpackAIFacebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAI | 21/7/2026 | 21/7/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack (versions 19.0.0 through 19.0.7, 19.1.0… | |
| Analizada | Media (5.3) | 0.52% | — | Webpack.js Webpack-dev-server | 3/7/2026 | 7/7/2026 | webpack-dev-server versions 5.2.5 and earlier terminate the whole Node.js process when an unauthenticated peer sends either a normal HTTP request with a malformed Host header or a WebSocket upgrade to the default /ws endpoint with a malformed Origin header. The malformed value causes an uncaught exception in the… | |
| Analizada | Media (4.7) | 0.52% | — | Webpack.js Webpack-dev-server | 3/7/2026 | 7/7/2026 | webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page. Any website a developer visits… | |
| Analizada | Media (4.3) | 0.23% | — | Webpack.js Webpack-dev-server | 15/6/2026 | 17/6/2026 | Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and… | |
| Analizada | Media (5.9) | 0.31% | — | Nuxt/rspack-builderNuxt/webpack-builder | 12/6/2026 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete fix for GHSA-6m52-m754-pw2g. Source code may still be stolen during dev when using the webpack / rspack builder if the… | |
| Analizada | Media (5.9) | 0.37% | — | Nuxt/rspack-builderNuxt/webpack-builder | 12/6/2026 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and 4.0.0-alpha.1 to before 4.4.6, there is an incomplete fix for GHSA-4gf7-ff8x-hq99. Source code may be stolen during dev when using the webpack / rspack builder if the dev… | |
| Analizada | Media (6.5) | 0.35% | — | Webpack.js Webpack-dev-server | 12/5/2026 | 17/6/2026 | webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustworthy origins,… | |
| Analizada | Alta (7.5) | 1.5% | — | Facebook React-server-dom-parcelFacebook React-server-dom-turbopackFacebook React-server-dom-webpack | 6/5/2026 | 12/8/2026 | A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to server crashes, out-of-memory exceptions or excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel,… | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Facebook React-server-dom-parcelAIFacebook React-server-dom-turbopackAIFacebook React-server-dom-webpackAI | 8/4/2026 | 25/7/2026 | A denial of service vulnerability exists in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack and react-server-dom-webpack (versions 19.0.0 through 19.0.4, 19.1.0 through 19.1.5, and 19.2.0 through 19.2.4). The vulnerability is triggered by sending specially… | |
| Analizada | Baja (3.7) | 0.21% | — | Webpack.js Webpack | 5/2/2026 | 17/6/2026 | Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies… | |
| Analizada | Baja (3.7) | 0.21% | — | Webpack.js Webpack | 5/2/2026 | 17/6/2026 | Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to… | |
| Aplazada | Crítica (9.8) | 0.33% | — | Eksagate Electronic Engineering AND Computer Industry Trade INC Webpack Management SystemAI | 19/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows SQL Injection. This issue affects Webpack Management System: through 20251119. | |
| Analizada | Media (6.5) | 0.34% | — | Webpack.js Webpack-dev-server | 3/6/2025 | 17/6/2026 | webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when you access a malicious web site with non-Chromium based browser. The `Origin` header is checked to prevent Cross-site WebSocket… | |
| Analizada | Media (5.9) | 0.57% | — | Webpack.js Webpack-dev-server | 3/6/2025 | 17/6/2026 | webpack-dev-server allows users to use webpack with a development server that provides live reloading. Prior to version 5.2.1, webpack-dev-server users' source code may be stolen when they access a malicious web site. Because the request for classic script by a script tag is not subject to same origin policy, an… | |
| Aplazada | Media (5.3) | 0.34% | — | NuxtAIRspackAIWebpack.js WebpackAI | 25/1/2025 | 17/6/2026 | Nuxt is an open-source web development framework for Vue.js. Source code may be stolen during dev when using version 3.0.0 through 3.15.12 of the webpack builder or version 3.12.2 through 3.152 of the rspack builder and a victim opens a malicious web site. Because the request for classic script by a script tag is not… | |
| Modificada | Media (6.1) | 0.96% | — | Webpack.js Webpack | 27/8/2024 | 17/6/2026 | Webpack is a module bundler. Its main purpose is to bundle JavaScript files for usage in a browser, yet it is also capable of transforming, bundling, or packaging just about any resource or asset. The webpack developers have discovered a DOM Clobbering vulnerability in Webpack’s `AutoPublicPathRuntimeModule`. The DOM… | |
| Analizada | Alta (7.5) | 1.2% | — | Webpack.js Webpack-dev-middleware | 21/3/2024 | 17/6/2026 | Prior to versions 7.1.0, 6.1.2, and 5.3.4, the webpack-dev-middleware development middleware for devpack does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the developer's machine. The middleware can either work with the physical filesystem… | |
| Modificada | Crítica (9.8) | 1.4% | — | Webpack.js Webpack | 13/3/2023 | 17/6/2026 | Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object. | |
| Modificada | Media (5.3) | 1.0% | — | Easyjs Easywebpack-cli | 15/12/2022 | 17/6/2026 | Directory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request. | |
| Modificada | Alta (7.5) | 2.2% | — | Webpack.js Loader-utils | 14/10/2022 | 17/6/2026 | A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js. | |
| Modificada | Crítica (9.8) | 2.9% | — | Webpack.js Loader-utilsDebian Linux | 12/10/2022 | 17/6/2026 | Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3. | |
| Modificada | Alta (7.5) | 2.2% | — | Webpack.js Loader-utils | 11/10/2022 | 17/6/2026 | A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js. | |
| Modificada | Baja (3.7) | 0.52% | — | Webpack-subresource-integrity Project Webpack-subresource-integrity | 19/10/2020 | 17/6/2026 | In webpack-subresource-integrity before version 1.5.1, all dynamically loaded chunks receive an invalid integrity hash that is ignored by the browser, and therefore the browser cannot validate their integrity. This removes the additional level of protection offered by SRI for such chunks. Top-level chunks are… | |
| Modificada | Alta (7.5) | 2.6% | — | Webpack.js Webpack-dev-server | 21/9/2018 | 17/6/2026 | An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a… |