webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
CVE-2026-6402 is a vulnerability affecting webpack-dev-server when used on non-HTTPS origins, leading to cross-origin source code exposure. The vulnerability is categorized under CWE-749, which relates to the improper protection of sensitive information. The affected products include Microsoft and Azure Linux versions 3.0. There is no CVSS score provided, and no known exploits in the wild have been reported. No patch or remediation information is currently available from the vendor advisory. The vulnerability could allow unauthorized access to source code when the server is accessed over non-secure (non-HTTPS) connections.
AI Analysis
Technical Summary
This vulnerability in webpack-dev-server allows cross-origin source code exposure when the server is accessed via non-HTTPS origins. It affects Microsoft and Azure Linux 3.0 versions. The issue is related to improper protection of sensitive information (CWE-749). No CVSS score or patch information is currently available, and no known exploits have been reported. The vendor advisory from Microsoft Security Response Center does not provide remediation details, and the service is not cloud-hosted, so remediation responsibility lies with the user.
Potential Impact
The vulnerability could lead to unauthorized disclosure of source code when webpack-dev-server is used on non-HTTPS origins. This exposure may aid attackers in understanding application internals, potentially facilitating further attacks. However, no known exploits in the wild have been reported, and the overall impact depends on the deployment context and whether non-HTTPS origins are used.
Mitigation Recommendations
Patch status is not yet confirmed — check the Microsoft Security Response Center advisory for current remediation guidance. Until a patch is available, users should avoid running webpack-dev-server on non-HTTPS origins to prevent source code exposure. Using HTTPS for development servers or restricting access to trusted networks may reduce risk.
webpack-dev-server vulnerable to cross-origin source code exposure on non-HTTPS origins
Description
CVE-2026-6402 is a vulnerability affecting webpack-dev-server when used on non-HTTPS origins, leading to cross-origin source code exposure. The vulnerability is categorized under CWE-749, which relates to the improper protection of sensitive information. The affected products include Microsoft and Azure Linux versions 3.0. There is no CVSS score provided, and no known exploits in the wild have been reported. No patch or remediation information is currently available from the vendor advisory. The vulnerability could allow unauthorized access to source code when the server is accessed over non-secure (non-HTTPS) connections.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in webpack-dev-server allows cross-origin source code exposure when the server is accessed via non-HTTPS origins. It affects Microsoft and Azure Linux 3.0 versions. The issue is related to improper protection of sensitive information (CWE-749). No CVSS score or patch information is currently available, and no known exploits have been reported. The vendor advisory from Microsoft Security Response Center does not provide remediation details, and the service is not cloud-hosted, so remediation responsibility lies with the user.
Potential Impact
The vulnerability could lead to unauthorized disclosure of source code when webpack-dev-server is used on non-HTTPS origins. This exposure may aid attackers in understanding application internals, potentially facilitating further attacks. However, no known exploits in the wild have been reported, and the overall impact depends on the deployment context and whether non-HTTPS origins are used.
Mitigation Recommendations
Patch status is not yet confirmed — check the Microsoft Security Response Center advisory for current remediation guidance. Until a patch is available, users should avoid running webpack-dev-server on non-HTTPS origins to prevent source code exposure. Using HTTPS for development servers or restricting access to trusted networks may reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-6402
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a175ef1e29bf47b50ede84b
Added to database: 05/27/2026, 21:15:29 UTC
Last enriched: 05/27/2026, 21:29:41 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 74
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.