CVE-2026-6402

Aliases:GHSA-79cf-xcqc-c78wCGA-2ff5-wm9r-2725CGA-2mmm-rr28-8pxjCGA-6rqr-3w47-m4wpCGA-7qq5-xrp6-7xwjCGA-835h-482c-h782CGA-8q9g-w8m8-8r3vCGA-9hmv-hvhg-83w9CGA-9xc2-cccp-pf4cCGA-cpw7-h49x-c3rfCGA-m9xx-6384-f58qCGA-p6jc-3h52-c8j5CGA-2522-9pc8-5wc3CGA-2945-pqjf-xq37CGA-2m83-gvp4-hvwxCGA-33f7-69gq-m69cCGA-37c5-j86w-cvwmCGA-37cj-rx2j-82w7CGA-38jm-gwx2-r286CGA-38pj-v5f4-hm78CGA-39xv-qq37-wvp7CGA-3fjm-rxw6-5hh8CGA-3m8c-2jrq-cqjjCGA-3m9m-v6cc-p783CGA-3pph-ghgq-5h9vCGA-3qvr-qmrp-399xCGA-3xr6-g5c4-xvxpCGA-5x8j-qxg8-qm23CGA-6xrm-m72w-x827CGA-72hj-c7gx-36pgCGA-7w9w-93x6-p434CGA-848w-pq8x-234hCGA-876r-gcr5-ffw8CGA-8fvr-9rw6-w8qrCGA-9m7m-w4ww-6vfpCGA-9x7h-phjp-4f38CGA-c589-9p83-5mfrCGA-c836-m2hc-jcjvCGA-cc67-hcvg-8w7vCGA-f43x-hcv2-gc8cCGA-f455-p6h9-x75vCGA-f837-5w47-3f94CGA-fx2x-wwmw-cq42CGA-g8vm-wfp9-rm9hCGA-gm57-xhqf-7q55CGA-gqgg-2qwx-c3v5CGA-hq78-8mp6-2wh7CGA-j4pp-vw52-xwh4CGA-j9wh-vghf-g2r9CGA-jgpg-jfrf-grfpCGA-jm2p-843r-rmv8CGA-p33w-3j8h-wp4gCGA-q29g-j2hg-43r8CGA-q532-p6qp-j5cjCGA-q9xp-9f2w-hwm2CGA-qcqx-f362-8ff3CGA-qfhr-xq74-22p8CGA-qp93-xrwf-wx8cCGA-qpfq-mv8c-gv45CGA-qwv4-527m-gg9cCGA-qxmc-cvg5-vp4jCGA-qxp2-ghgv-94xxCGA-r455-8p4g-5f4jCGA-rpqf-wmmg-r9pgCGA-vrq8-4978-wmxrCGA-w9hp-8r47-f46xCGA-wc2c-5wxv-37f9CGA-wpch-gjch-4p2cCGA-wpmw-ffjc-mmv5CGA-wwph-cj75-pw9pCGA-x246-hxwq-92f2CGA-x36h-hr4q-9rp2CGA-xgwp-fv3p-gcf4CGA-xp2w-f3vx-f9j4CGA-xxcm-5859-mh2vCGA-66p6-mgp3-pp3rCGA-p2gw-gcxr-h65c
Advisory lineage Upstream: 0 Downstream: 1
Analyzed
Published: 12 May 2026, 07:45
Last modified:12 May 2026, 13:00

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.29% LOW
0% probability +0.07%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 May 2026, 07:45
Published
Vulnerability first disclosed
12 May 2026, 13:00
Last Modified
Vulnerability information updated

Description

webpack-dev-server versions up to and including 5.2.3 are vulnerable to cross-origin source code exposure when serving over a non-potentially trustworthy origin such as plain HTTP. The previous fix relied on the Sec-Fetch-Mode and Sec-Fetch-Site request headers, which browsers omit for non-trustworthy origins, allowing a malicious site to load the bundled source as a script and read it across origins. Impact: an attacker controlling a website visited by a developer running webpack-dev-server can recover the application source code when the dev server runs over HTTP at a guessable host and port. Chromium based browsers from Chrome 142 onward are not affected due to local network access restrictions. Upgrade to webpack-dev-server 5.2.4 or later, which sets Cross-Origin-Resource-Policy: same-origin on responses.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.29% Percentile: 22%

Techniques & Countermeasures

  • CWE-749Exposed Dangerous Method or Function

    The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Affected Systems

  • chainguardarangodb-3.11

    all | < 3.11.14.5-r25

  • chainguardarangodb-3.12

    all | < 3.12.11-r0

  • chainguardargo-workflows-ui-3.6

    < 3.6.19-r7

  • chainguardgitlab-rails-ce-18.1

    all

  • chainguardgitlab-rails-ce-18.10

    all

  • chainguardgitlab-rails-ce-18.11

    all

  • chainguardgitlab-rails-ce-18.5

    all

  • chainguardgitlab-rails-ce-18.6

    all

  • chainguardgitlab-rails-ce-18.7

    all

  • chainguardgitlab-rails-ce-18.8

    all

  • chainguardgitlab-rails-ce-18.9

    all

  • chainguardgitlab-rails-ce-19.0

    all

  • chainguardgitlab-rails-ce-19.1

    all | < 19.1.7-r6

  • chainguardgitlab-rails-ce-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-19.3

    < 19.3.1-r6

  • chainguardgitlab-rails-ce-fips-18.1

    all

  • chainguardgitlab-rails-ce-fips-18.10

    all

  • chainguardgitlab-rails-ce-fips-18.11

    all

  • chainguardgitlab-rails-ce-fips-18.5

    all

  • chainguardgitlab-rails-ce-fips-18.6

    all

  • chainguardgitlab-rails-ce-fips-18.7

    all

  • chainguardgitlab-rails-ce-fips-18.8

    all

  • chainguardgitlab-rails-ce-fips-18.9

    all

  • chainguardgitlab-rails-ce-fips-19.0

    all

  • chainguardgitlab-rails-ce-fips-19.1

    all | < 19.1.7-r7

  • chainguardgitlab-rails-ce-fips-19.2

    all | < 19.2.5-r2

  • chainguardgitlab-rails-ce-fips-19.3

    < 19.3.1-r3

  • chainguardkatib-earlystopping

    < 0.19.0-r31

  • chainguardkatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • chainguardkatib-suggestion-hyperband

    < 0.19.0-r31

  • chainguardkatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • chainguardkatib-suggestion-nas-darts

    < 0.19.0-r31

  • chainguardkatib-suggestion-nas-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-optuna-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-pbt-enas

    < 0.19.0-r31

  • chainguardkatib-suggestion-skopt-enas

    < 0.19.0-r31

  • chainguardkatib-tfevent-metricscollector

    < 0.19.0-r31

  • wolfikatib-earlystopping

    < 0.19.0-r31

  • wolfikatib-suggestion-goptuna-compat

    < 0.19.0-r40

  • wolfikatib-suggestion-hyperband

    < 0.19.0-r31

  • wolfikatib-suggestion-hyperopt

    < 0.19.0-r31 | < 0.19.0-r40

  • wolfikatib-suggestion-nas-darts

    < 0.19.0-r31

  • wolfikatib-suggestion-nas-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-optuna-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-pbt-enas

    < 0.19.0-r31

  • wolfikatib-suggestion-skopt-enas

    < 0.19.0-r31

  • wolfikatib-tfevent-metricscollector

    < 0.19.0-r31

  • Npmwebpack-dev-server

    < 5.2.4

  • webpack-dev-serverwebpack-dev-server

    < 5.2.4

  • webpack.jswebpack-dev-server

    < 5.2.4

References (7)