Skip to content

Bump webpack-dev-server from 4.15.0 to 5.2.4 - #334

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/webpack-dev-server-5.2.4
Closed

Bump webpack-dev-server from 4.15.0 to 5.2.4#334
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/webpack-dev-server-5.2.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 19, 2026

Copy link
Copy Markdown

Bumps webpack-dev-server from 4.15.0 to 5.2.4.

Release notes

Sourced from webpack-dev-server's releases.

v5.2.4

5.2.4 (2026-05-11)

Bug Fixes

  • set Cross-Origin-Resource-Policy header to prevent source code theft over HTTP

v5.2.3

5.2.3 (2026-01-12)

Bug Fixes

  • add cause for errorObject (#5518) (37b033d)
  • compatibility with event target and universal target and lazy compilation (574026c)
  • overlay: add ESC key to dismiss overlay (#5598) (f91baa8)
  • progress indicator styles (#5557) (41a53a1)
  • upgrade selfsigned to v5

v5.2.2

5.2.2 (2025-06-03)

Bug Fixes

  • "Overlay enabled" false positive (18e72ee)
  • do not crush when error is null for runtime errors (#5447) (309991f)
  • remove unnecessary header X_TEST (#5451) (64a6124)
  • respect the allowedHosts option for cross-origin header check (#5510) (03d1214)

v5.2.1

5.2.1 (2025-03-26)

Security

  • cross-origin requests are not allowed unless allowed by Access-Control-Allow-Origin header
  • requests with an IP addresses in the Origin header are not allowed to connect to WebSocket server unless configured by allowedHosts or it different from the Host header

The above changes may make the dev server not work if you relied on such behavior, but unfortunately they carry security risks, so they were considered as fixes.

Bug Fixes

  • prevent overlay for errors caught by React error boundaries (#5431) (8c1abc9)
  • take the first network found instead of the last one, this restores the same behavior as 5.0.4 (#5411) (ffd0b86)

v5.2.0

5.2.0 (2024-12-11)

Features

... (truncated)

Changelog

Sourced from webpack-dev-server's changelog.

5.2.4 (2026-05-11)

Bug Fixes

  • set Cross-Origin-Resource-Policy header to prevent source code theft over HTTP

5.2.3 (2026-01-12)

Bug Fixes

  • add cause for errorObject (#5518) (37b033d)
  • compatibility with event target and universal target and lazy compilation (574026c)
  • overlay: add ESC key to dismiss overlay (#5598) (f91baa8)
  • progress indicator styles (#5557) (41a53a1)
  • upgrade selfsigned to v5

5.2.2 (2025-06-03)

Bug Fixes

  • "Overlay enabled" false positive (18e72ee)
  • do not crush when error is null for runtime errors (#5447) (309991f)
  • remove unnecessary header X_TEST (#5451) (64a6124)
  • respect the allowedHosts option for cross-origin header check (#5510) (03d1214)

5.2.1 (2025-03-26)

Security

  • cross-origin requests are not allowed unless allowed by Access-Control-Allow-Origin header
  • requests with an IP addresses in the Origin header are not allowed to connect to WebSocket server unless configured by allowedHosts or it different from the Host header

The above changes may make the dev server not work if you relied on such behavior, but unfortunately they carry security risks, so they were considered as fixes.

Bug Fixes

  • prevent overlay for errors caught by React error boundaries (#5431) (8c1abc9)
  • take the first network found instead of the last one, this restores the same behavior as 5.0.4 (#5411) (ffd0b86)

5.2.0 (2024-12-11)

Features

  • added getClientEntry and getClientHotEntry methods to get clients entries (dc642a8)

Bug Fixes

... (truncated)

Commits
Install script changes

This version modifies prepare script that runs during installation. Review the package contents before updating.


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [webpack-dev-server](https://github.com/webpack/webpack-dev-server) from 4.15.0 to 5.2.4.
- [Release notes](https://github.com/webpack/webpack-dev-server/releases)
- [Changelog](https://github.com/webpack/webpack-dev-server/blob/main/CHANGELOG.md)
- [Commits](webpack/webpack-dev-server@v4.15.0...v5.2.4)

---
updated-dependencies:
- dependency-name: webpack-dev-server
  dependency-version: 5.2.4
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 19, 2026
@martinSaad

Copy link
Copy Markdown

Snyk checks have failed. 378 issues have been found so far.

Status Scan Engine Critical High Medium Low Total (378)
Open Source Security 25 222 110 21 378 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

@socket-security

Copy link
Copy Markdown

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Critical
Critical CVE: Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code in npm babel-traverse

CVE: GHSA-67hx-6x53-jw92 Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code (CRITICAL)

Affected versions: >= 0

Patched version: No patched versions

From: ?npm/react-scripts@0.9.5npm/babel-traverse@6.26.0

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/babel-traverse@6.26.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Exposure of Sensitive Information in npm eventsource

CVE: GHSA-6h5x-7c5m-7cr7 Exposure of Sensitive Information in eventsource (CRITICAL)

Affected versions: < 1.1.1; >= 2.0.0 < 2.0.2

Patched version: 1.1.1

From: ?npm/react-scripts@0.9.5npm/eventsource@0.1.6

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/eventsource@0.1.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm form-data uses unsafe random function in form-data for choosing boundary

CVE: GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary (CRITICAL)

Affected versions: < 2.5.4; >= 3.0.0 < 3.0.4; >= 4.0.0 < 4.0.4

Patched version: 2.5.4

From: ?npm/react-scripts@0.9.5npm/form-data@2.1.4

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/form-data@2.1.4. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm form-data uses unsafe random function in form-data for choosing boundary

CVE: GHSA-fjxv-7rqg-78g4 form-data uses unsafe random function in form-data for choosing boundary (CRITICAL)

Affected versions: < 2.5.4; >= 3.0.0 < 3.0.4; >= 4.0.0 < 4.0.4

Patched version: 2.5.4

From: ?npm/react-scripts@0.9.5npm/form-data@2.3.3

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/form-data@2.3.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Code injection in npm fsevents

CVE: GHSA-8r6j-v8pm-fqw3 Code injection in fsevents (CRITICAL)

Affected versions: < 1.2.11

Patched version: 1.2.11

From: ?npm/react-scripts@0.9.5npm/fsevents@1.0.17

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/fsevents@1.0.17. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Handlebars.js has JavaScript Injection via AST Type Confusion

CVE: GHSA-2w6w-674q-4c4q Handlebars.js has JavaScript Injection via AST Type Confusion (CRITICAL)

Affected versions: >= 4.0.0 < 4.7.9

Patched version: 4.7.9

From: ?npm/react-scripts@0.9.5npm/handlebars@4.7.7

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/handlebars@4.7.7. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm json-schema is vulnerable to Prototype Pollution

CVE: GHSA-896r-f27r-55mw json-schema is vulnerable to Prototype Pollution (CRITICAL)

Affected versions: < 0.4.0

Patched version: 0.4.0

From: ?npm/react-scripts@0.9.5npm/json-schema@0.2.3

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/json-schema@0.2.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Command Injection in npm open

CVE: GHSA-28xh-wpgr-7fm8 Command Injection in open (CRITICAL)

Affected versions: < 6.0.0

Patched version: 6.0.0

From: ?npm/open@0.0.5

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/open@0.0.5. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: npm sha.js is missing type checks leading to hash rewind and passing on crafted data

CVE: GHSA-95m3-7q98-8xr5 sha.js is missing type checks leading to hash rewind and passing on crafted data (CRITICAL)

Affected versions: < 2.4.12

Patched version: 2.4.12

From: ?npm/sha.js@2.2.6

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/sha.js@2.2.6. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Critical
Critical CVE: Authorization Bypass Through User-Controlled Key in npm url-parse

CVE: GHSA-hgjh-723h-mx2j Authorization Bypass Through User-Controlled Key in url-parse (CRITICAL)

Affected versions: < 1.5.8

Patched version: 1.5.8

From: ?npm/react-scripts@0.9.5npm/url-parse@1.5.1

ℹ Read more on: This package | This alert | What is a critical CVE?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Remove or replace dependencies that include known critical CVEs. Consumers can use dependency overrides or npm audit fix --force to remove vulnerable dependencies.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/url-parse@1.5.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: npm buffer is 96.0% likely obfuscated

Confidence: 0.96

Location: Package overview

From: ?npm/buffer@4.9.2

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/buffer@4.9.2. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@karencapiiro

Copy link
Copy Markdown

Logo
Checkmarx One – Scan Summary & Details11d170ea-b916-4594-860a-670c874844ae


New Issues (287) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 CRITICAL CVE-2026-0905 Npm-electron-23.1.2
detailsDescription: Insufficient policy enforcement in the Network in Google Chrome prior to 144.0.7559.59 allowed an attacker who obtained a network log file to poten...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 5tBps9BiPy9EIuPmruQq1yQQVQfTQAzPYn3jnPve9vQ%3D
Vulnerable Package
2 CRITICAL CVE-2026-0906 Npm-electron-23.1.2
detailsDescription: Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: jIqcDA%2Fi6d%2FfNox4mW%2BBzwF5NINI99m%2FWjrfrtZS0hE%3D
Vulnerable Package
3 CRITICAL CVE-2026-0907 Npm-electron-23.1.2
detailsDescription: Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
Attack Vector: NETWORK
Attack Complexity: LOW

ID: f9heV6tHgLdB0SH3vYO3b%2FX4FCnxqNey624XpVf8RO0%3D
Vulnerable Package
4 CRITICAL CVE-2026-1525 Npm-undici-5.20.0
detailsDescription: Undici versions prior to 6.24.0 and 7.0.x prior to 7.24.0 allow duplicate HTTPContent-Length headers when they are provided in an array with case-v...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 4S01aV2945w6PWpXx1u2WDQpFyg4CDIsnOqV638n9qI%3D
Vulnerable Package
5 CRITICAL CVE-2026-1525 Npm-undici-5.22.1
detailsDescription: Undici versions prior to 6.24.0 and 7.0.x prior to 7.24.0 allow duplicate HTTPContent-Length headers when they are provided in an array with case-v...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Bobv4DRtfgD%2FDTnxDqm8Xyt7JqCLmn6TP6rLYBsNOGU%3D
Vulnerable Package
6 CRITICAL CVE-2026-3061 Npm-electron-23.1.2
detailsDescription: Out-of-bounds Read in Media in Google Chrome prior to 145.0.7632.116 allowed a remote attacker to perform an out of bounds memory read via a crafte...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: X2wnhjPtpCv5syHjpAtaN850HWhnoub9UyQZe6wmyok%3D
Vulnerable Package
7 CRITICAL CVE-2026-3062 Npm-electron-23.1.2
detailsDescription: Out-of-bounds Read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory acce...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: mwCzdcBoAd0jKm6LCo04hEt9F30P5hBtMnLInBXK8Sk%3D
Vulnerable Package
8 CRITICAL CVE-2026-33896 Npm-node-forge-0.10.0
detailsDescription: `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 60f8sBbFdbQK54TqA0iRFB5Gao60%2FSFJGgJGI4SEGJ4%3D
Vulnerable Package
9 CRITICAL CVE-2026-33896 Npm-node-forge-0.6.33
detailsDescription: `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HC%2FKab%2BYD77BhotKUphDS43QUUH1J5V1W%2FpQc2Nvc4A%3D
Vulnerable Package
10 CRITICAL CVE-2026-33896 Npm-node-forge-0.7.6
detailsDescription: `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstraints requirements when an intermediate certificate lacks both the `basicConstr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: jVIlFBgz2lBzm8f9GoZKBw5LzBdTzHaHHCFpGhIDUHk%3D
Vulnerable Package
11 CRITICAL CVE-2026-33937 Npm-handlebars-4.5.3
detailsDescription: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 0wvBYdiGoh%2BAoFC0uotKJmwL6Al4zkQlNfh48NBbRAI%3D
Vulnerable Package
12 CRITICAL CVE-2026-33937 Npm-handlebars-4.7.6
detailsDescription: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: bWVk23tVuAld6JQSDhdFfpu5coStm%2FcZdKb8pb4L0AY%3D
Vulnerable Package
13 CRITICAL CVE-2026-33937 Npm-handlebars-4.7.7
detailsDescription: Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: gOG07bt655pbzqWrjOYxwkVHAUVuHTOmUoslGiT%2BqyM%3D
Vulnerable Package
14 CRITICAL CVE-2026-34775 Npm-electron-23.1.2
detailsDescription: Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.x prior to 39....
Attack Vector: NETWORK
Attack Complexity: LOW

ID: WqvCTiABeuIq2aJaM%2BjNEXESM%2FoMb9p%2FFeHz7nM389I%3D
Vulnerable Package
15 CRITICAL CVE-2026-3545 Npm-electron-23.1.2
detailsDescription: Insufficient data validation in Navigation in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform a sandbox esca...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: jC2Rt2MU%2FWtLkHBu8WEFwJaWDehKuOf%2FidP9qGlfpm0%3D
Vulnerable Package
16 CRITICAL CVE-2026-3916 Npm-electron-23.1.2
detailsDescription: Out-of-bounds Read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a cr...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: B9i9ABR35mTbWerd1yH6Xn8lOx%2B1MTM9VNg9IRfhRuw%3D
Vulnerable Package
17 CRITICAL CVE-2026-4800 Npm-lodash-4.17.4
detailsDescription: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: fa1%2BkM95VKREFAqI4ng555a9Cp4czb44nL6Y3cMhVXg%3D
Vulnerable Package
18 CRITICAL CVE-2026-4800 Npm-lodash-4.17.15
detailsDescription: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: PcLoe7AT2vjXIxsggALkIiumwHc6%2B%2FWkX%2FTJIv2pGhk%3D
Vulnerable Package
19 CRITICAL CVE-2026-4800 Npm-lodash-4.17.11
detailsDescription: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: xhmI1pd263xYiPrOCq%2FJBi8EbZPUQowlCMny9oUhl44%3D
Vulnerable Package
20 CRITICAL CVE-2026-4800 Npm-lodash-4.17.20
detailsDescription: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: YM5aLr768hSdObLkw3oIfG8NGx9A6fXP86bGw9RI4tY%3D
Vulnerable Package
21 CRITICAL CVE-2026-4800 Npm-lodash-4.17.21
detailsDescription: The fix for CVE-2021-23337 added validation for the variable option in _.template but did not apply the same validation to "options.imports" key na...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Yualp2%2BFbkjSyi70Vuc7%2BVR5EnPlarFBGh11NE87IDM%3D
Vulnerable Package
22 CRITICAL CVE-2026-5288 Npm-electron-23.1.2
detailsDescription: Use after free in WebView in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: yyt79AfWZvcl3X6jhTnvCgrqN3IwdT1wccd3o0AaHi8%3D
Vulnerable Package
23 CRITICAL Cx0a53ef16-dcb9 Npm-react-devtools-shared-0.0.1
detailsDescription: This package was manually inspected by a security researcher and flagged as malicious ### About Classifying malicious packages is an internal proc...

ID: bkVQcS3BfbGqVMPm7rCIJLHEoWERm8sJ35U%2FHpppsN4%3D
Vulnerable Package
24 HIGH CVE-2023-1220 Npm-electron-23.1.2
detailsDescription: Heap-based Buffer Overflow in UMA in Google Chrome prior to 111.0.5563.64 allowed a remote attacker who had compromised the renderer process to pot...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: MUpqYicIdgDNS1QUVotHYtJDMa3FZxO3jhxSK6TVlVw%3D
Vulnerable Package
25 HIGH CVE-2023-1530 Npm-electron-23.1.2
detailsDescription: Use after free in PDF in Google Chrome versions prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a craf...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: FRBv0ZDN8245tfX7%2Fz%2FyIqPnHGpcPnDibtSMglOvqXo%3D
Vulnerable Package
26 HIGH CVE-2023-1811 Npm-electron-23.1.2
detailsDescription: Use after free in Frames in Google Chrome in versions prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific U...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Sx9QWHj3Y1mZ2P8iTuHnSf1nc5QPPMCUzlxAb%2Bt%2BKUU%3D
Vulnerable Package
27 HIGH CVE-2023-2135 Npm-electron-23.1.2
detailsDescription: Use After Free in DevTools in Google Chrome in versions prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific p...
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: %2FbChPMnxC7UADh7V%2BlKusk3%2B17itfuR9mqUIFkWwxrM%3D
Vulnerable Package
28 HIGH CVE-2025-13630 Npm-electron-23.1.2
detailsDescription: Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attack Vector: NETWORK
Attack Complexity: LOW

ID: mO2aj1t4ASCKSbdGli%2Fe9xkvD1lgCvH9BZhcQi%2F%2BZx8%3D
Vulnerable Package
29 HIGH CVE-2025-13631 Npm-electron-23.1.2
detailsDescription: Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker to perform Privilege Escala...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: Xt2nRy2s6d8%2FjIobIAFzPtDa6MKU8h%2Fc1RKnl%2FMRhj0%3D
Vulnerable Package
30 HIGH CVE-2025-13633 Npm-electron-23.1.2
detailsDescription: Use After Free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: %2FFCrGehZ7W4zYDooaRiWnNPYGXkOCwFml4%2FsMPjkN7U%3D
Vulnerable Package
31 HIGH CVE-2025-13638 Npm-electron-23.1.2
detailsDescription: Use After Free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a craft...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: XBDzj9YQ0EhOnWCKZ4KD%2Bvd9IFDDGfyWGsxfyYuK1pY%3D
Vulnerable Package
32 HIGH CVE-2025-13639 Npm-electron-23.1.2
detailsDescription: Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a craf...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: P3FUOoq7BNHWkbvs52BCUW1IhVpUzWtb882f7YDtirw%3D
Vulnerable Package
33 HIGH CVE-2025-13720 Npm-electron-23.1.2
detailsDescription: Bad cast in Loader in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploi...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: zCDrYlm8yS8DR4wylcnskYcHEQeFHuLIyfyl5xPUQOM%3D
Vulnerable Package
34 HIGH CVE-2025-13721 Npm-electron-23.1.2
detailsDescription: Race in v8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Attack Vector: NETWORK
Attack Complexity: HIGH

ID: 8zXCpPn0JkBwXk8dZ51CWUYHtNwSjV2Y9%2BIAhNsKBls%3D
Vulnerable Package
35 HIGH CVE-2025-14174 Npm-electron-23.1.2
detailsDescription: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory acce...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: gs%2FeKdxsvGNAAMkcD2lHOyqDmBIL1AB06wuq8pNYJpA%3D
Vulnerable Package
36 HIGH CVE-2025-14765 Npm-electron-23.1.2
detailsDescription: Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HT...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: EUt%2BnsszrrpFgBSxhRtFFBQ16%2FXW12RvKDy%2F%2B7D52dA%3D
Vulnerable Package
37 HIGH CVE-2025-14766 Npm-electron-23.1.2
detailsDescription: Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: HDnKXYETr9AbW%2BkufKzqoSwxOBiqnnDdts5fOH%2BXiks%3D
Vulnerable Package
38 HIGH CVE-2026-0628 Npm-electron-23.1.2
detailsDescription: Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malic...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 6GzTFOG72wTS9jPxuC7l9%2FHFgsQuUPheayFz4QPbtZA%3D
Vulnerable Package
39 HIGH CVE-2026-0899 Npm-electron-23.1.2
detailsDescription: Out of bounds memory access in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: 9D6FWV0aIS7p%2BxHMxFKNlar%2Fx6gWR%2FMm7J3iL0NHKpM%3D
Vulnerable Package
40 HIGH CVE-2026-0900 Npm-electron-23.1.2
detailsDescription: Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: wVI%2F%2FYzuIprxtiSI%2BW3dYOREymx8me7qMLmu34QV3So%3D
Vulnerable Package
41 HIGH CVE-2026-0902 Npm-electron-23.1.2
detailsDescription: Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory read via a ...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: dsUBTW0BH35XRUNr5sJnEKMHe5rmx0lgGQbHd0Hz1Fs%3D
Vulnerable Package
42 HIGH CVE-2026-0908 Npm-electron-23.1.2
detailsDescription: Use-after-free in ANGLE in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: qo6Mj41RHs9qm4%2FoG2sTGU36ECcRTRYRdXqwqfU397M%3D
Vulnerable Package
43 HIGH CVE-2026-1526 Npm-undici-5.20.0
detailsDescription: The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. W...
Attack Vector: NETWORK
Attack Complexity: LOW

ID: J7XGTKQ5qYvx6lx1srf%2BNY%2Fdbi6CwVlVDCyrO4fBID0%3D
Vulnerable Package

More results are available on the CxOne platform


Fixed Issues (7) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
MEDIUM CVE-2025-13466 Npm-body-parser-1.19.2
MEDIUM CVE-2025-13466 Npm-body-parser-1.19.0
MEDIUM CVE-2025-13466 Npm-body-parser-1.18.2
MEDIUM CVE-2025-13466 Npm-body-parser-1.20.1
MEDIUM CVE-2025-13466 Npm-body-parser-1.20.2
MEDIUM CVE-2025-32996 Npm-http-proxy-middleware-2.0.6
MEDIUM CVE-2025-32997 Npm-http-proxy-middleware-2.0.6

Communicate with Checkmarx by submitting a PR comment with @Checkmarx followed by one of the supported commands. Learn about the supported commands here.

@dependabot @github

dependabot Bot commented on behalf of github Jun 20, 2026

Copy link
Copy Markdown
Author

Superseded by #348.

@dependabot dependabot Bot closed this Jun 20, 2026
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/webpack-dev-server-5.2.4 branch June 20, 2026 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants