Update dependency webpack-dev-middleware to v7 [SECURITY] - #5373
renovate[bot] wants to merge 1 commit into
Conversation
⚠ Artifact update problemRenovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is. ♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below: File name: yarn.lock |
398a6a5 to
1c3d0fb
Compare
1c3d0fb to
9d0c985
Compare
9d0c985 to
e2060f3
Compare
430c158 to
e8de645
Compare
eb4093c to
1198166
Compare
1198166 to
ca1f55a
Compare
ca1f55a to
4435207
Compare
|
4435207 to
62748b6
Compare
62748b6 to
40378cd
Compare
af90a40 to
6918d8d
Compare
2a6bf5a to
c5cc8bd
Compare
c5cc8bd to
332cf85
Compare
332cf85 to
83b453f
Compare
7b32b29 to
a30ff17
Compare
9121f54 to
ed52b70
Compare
ed52b70 to
8ac3761
Compare
8ac3761 to
8d10f27
Compare
8d10f27 to
dcc189e
Compare
| "webpack-bundle-tracker": "^0.4.3", | ||
| "webpack-cli": "^3.3.10", | ||
| "webpack-dev-middleware": "^1.9.0", | ||
| "webpack-dev-middleware": "^5.0.0", |
There was a problem hiding this comment.
Bug: Upgrading webpack-dev-middleware to v5 while using webpack v4 will cause a runtime error, as v5 requires webpack v5. This will break the development server.
Severity: CRITICAL
Suggested Fix
To resolve this incompatibility, either upgrade webpack to version 5.0.0 or higher to match the webpack-dev-middleware requirement, or find a version of webpack-dev-middleware that is compatible with webpack v4 and also contains the necessary security fix.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: package.json#L132
Potential issue: The project upgrades `webpack-dev-middleware` to version `^5.0.0` but
continues to use `webpack` version `^4.46.0`. `webpack-dev-middleware` v5 has a peer
dependency on `webpack` v5 and is not backward compatible. When the development server
in `hot-reload-dev-server.js` initializes the middleware, it passes a `webpack` v4
compiler object. The middleware expects a `webpack` v5 compiler, and the mismatch in
APIs will cause a runtime error, preventing the development server from starting. This
will block all local development workflows.
Did we get this right? 👍 / 👎 to inform future reviews.
87a3c00 to
82ff367
Compare
| "webpack-bundle-tracker": "^0.4.3", | ||
| "webpack-cli": "^3.3.10", | ||
| "webpack-dev-middleware": "^1.9.0", | ||
| "webpack-dev-middleware": "^5.0.0", |
There was a problem hiding this comment.
Bug: The webpack-dev-middleware v5 upgrade is incompatible with the project's webpack v4 without manual configuration, which will cause the development server to crash on startup.
Severity: CRITICAL
Suggested Fix
To resolve the incompatibility, either upgrade webpack to v5, or manually configure the outputFileSystem for webpack-dev-middleware. If staying with webpack v4, you must provide an outputFileSystem instance that has the required .join() and mkdirp methods.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: package.json#L132
Potential issue: The project's `webpack` version is `^4.46.0`, but
`webpack-dev-middleware` is being upgraded to v5. Version 5 of `webpack-dev-middleware`
is designed for `webpack` v5 and has breaking changes when used with `webpack` v4.
Specifically, it requires the `outputFileSystem` to have `.join()` and `mkdirp` methods,
which are not provided by default in the `webpack` v4 environment. Since the code does
not manually configure the `outputFileSystem`, the development server will fail to
start, preventing developers from running the application locally.
ee19901 to
fd92412
Compare
fd92412 to
cc23e9b
Compare
| "webpack-bundle-tracker": "^0.4.3", | ||
| "webpack-cli": "^3.3.10", | ||
| "webpack-dev-middleware": "^1.9.0", | ||
| "webpack-dev-middleware": "^5.0.0", |
There was a problem hiding this comment.
Bug: The upgrade of webpack-dev-middleware to v5 is incompatible with the project's existing webpack v4 dependency, which will break the development server.
Severity: CRITICAL
Suggested Fix
To resolve this incompatibility, either upgrade webpack to version 5 alongside the webpack-dev-middleware upgrade, or revert the webpack-dev-middleware upgrade to a version compatible with webpack v4.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: package.json#L132
Potential issue: The pull request updates `webpack-dev-middleware` to version 5.0.0
while `webpack` remains at version 4.46.0. `webpack-dev-middleware` v5 has a peer
dependency requirement for `webpack` v5. The development server, initiated via
`hot-reload-dev-server.js`, passes a `webpack` v4 compiler instance to the
`webpack-dev-middleware`. This will cause a runtime crash during initialization because
the middleware will attempt to use webpack v5 APIs that do not exist in webpack v4,
breaking the local development workflow.
7d6d4d7 to
760c1e5
Compare
bb28f0d to
2a9d0e8
Compare
This PR contains the following updates:
^1.9.0→^7.0.0Path traversal in webpack-dev-middleware
CVE-2024-29180 / GHSA-wr3j-pwj9-hqq6
More information
Details
Summary
The webpack-dev-middleware middleware does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the developer's machine.
Details
The middleware can either work with the physical filesystem when reading the files or it can use a virtualized in-memory memfs filesystem.
If writeToDisk configuration option is set to true, the physical filesystem is used:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/setupOutputFileSystem.js#L21
The getFilenameFromUrl method is used to parse URL and build the local file path.
The public path prefix is stripped from the URL, and the unsecaped path suffix is appended to the outputPath:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/getFilenameFromUrl.js#L82
As the URL is not unescaped and normalized automatically before calling the midlleware, it is possible to use %2e and %2f sequences to perform path traversal attack.
PoC
A blank project can be created containing the following configuration file webpack.config.js:
module.exports = { devServer: { devMiddleware: { writeToDisk: true } } };When started, it is possible to access any local file, e.g. /etc/passwd:
$ curl localhost:8080/public/..%2f..%2f..%2f..%2f../etc/passwdImpact
The developers using webpack-dev-server or webpack-dev-middleware are affected by the issue. When the project is started, an attacker might access any file on the developer's machine and exfiltrate the content (e.g. password, configuration files, private source code, ...).
If the development server is listening on a public IP address (or 0.0.0.0), an attacker on the local network can access the local files without any interaction from the victim (direct connection to the port).
If the server allows access from third-party domains (CORS, Allow-Access-Origin: * ), an attacker can send a malicious link to the victim. When visited, the client side script can connect to the local server and exfiltrate the local files.
Recommendation
The URL should be unescaped and normalized before any further processing.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
CVE-2026-76844 / GHSA-g84c-rxfj-3j2c
More information
Details
Impact
webpack-dev-middlewareresolves a request to a local file ingetFilenameFromUrl. When the configuredpublicPathhas no trailing slash (for example/assets), a request that shares that prefix without being under it (for example/assets../secret) still passes the containment check, and the..guard does not catch it because it runs on the path before thepublicPathprefix is stripped. The stripped remainder then escapes the configured output directory once joined, so an unauthenticated request can read files outside the output root. Applications servingwebpack-dev-middleware(directly or viawebpack-dev-server) with apublicPaththat does not end in a slash are affected. A development server reachable on the network can be attacked with a single request and no victim interaction.Patches
Patched in
webpack-dev-middleware8.3.0. There is no backport to the 5.x, 6.x, or 7.x lines; users on those lines should upgrade to 8.3.0 or later.Workarounds
Configure
publicPathwith a trailing slash (for example/assets/instead of/assets), or upgrade to a patched version.References
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Path traversal in webpack-dev-middleware
CVE-2024-29180 / CVE-2026-76844 / GHSA-g84c-rxfj-3j2c / GHSA-wr3j-pwj9-hqq6
More information
Details
Summary
The webpack-dev-middleware middleware does not validate the supplied URL address sufficiently before returning the local file. It is possible to access any file on the developer's machine.
Details
The middleware can either work with the physical filesystem when reading the files or it can use a virtualized in-memory memfs filesystem.
If writeToDisk configuration option is set to true, the physical filesystem is used:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/setupOutputFileSystem.js#L21
The getFilenameFromUrl method is used to parse URL and build the local file path.
The public path prefix is stripped from the URL, and the unsecaped path suffix is appended to the outputPath:
https://github.com/webpack/webpack-dev-middleware/blob/7ed24e0b9f53ad1562343f9f517f0f0ad2a70377/src/utils/getFilenameFromUrl.js#L82
As the URL is not unescaped and normalized automatically before calling the midlleware, it is possible to use %2e and %2f sequences to perform path traversal attack.
PoC
A blank project can be created containing the following configuration file webpack.config.js:
module.exports = { devServer: { devMiddleware: { writeToDisk: true } } };When started, it is possible to access any local file, e.g. /etc/passwd:
$ curl localhost:8080/public/..%2f..%2f..%2f..%2f../etc/passwdImpact
The developers using webpack-dev-server or webpack-dev-middleware are affected by the issue. When the project is started, an attacker might access any file on the developer's machine and exfiltrate the content (e.g. password, configuration files, private source code, ...).
If the development server is listening on a public IP address (or 0.0.0.0), an attacker on the local network can access the local files without any interaction from the victim (direct connection to the port).
If the server allows access from third-party domains (CORS, Allow-Access-Origin: * ), an attacker can send a malicious link to the victim. When visited, the client side script can connect to the local server and exfiltrate the local files.
Recommendation
The URL should be unescaped and normalized before any further processing.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
CVE-2024-29180 / CVE-2026-76844 / GHSA-g84c-rxfj-3j2c / GHSA-wr3j-pwj9-hqq6
More information
Details
Impact
webpack-dev-middlewareresolves a request to a local file ingetFilenameFromUrl. When the configuredpublicPathhas no trailing slash (for example/assets), a request that shares that prefix without being under it (for example/assets../secret) still passes the containment check, and the..guard does not catch it because it runs on the path before thepublicPathprefix is stripped. The stripped remainder then escapes the configured output directory once joined, so an unauthenticated request can read files outside the output root. Applications servingwebpack-dev-middleware(directly or viawebpack-dev-server) with apublicPaththat does not end in a slash are affected. A development server reachable on the network can be attacked with a single request and no victim interaction.Patches
Patched in
webpack-dev-middleware8.3.0. There is no backport to the 5.x, 6.x, or 7.x lines; users on those lines should upgrade to 8.3.0 or later.Workarounds
Configure
publicPathwith a trailing slash (for example/assets/instead of/assets), or upgrade to a patched version.References
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
webpack/webpack-dev-middleware (webpack-dev-middleware)
v7.4.6Compare Source
7.4.6 (2026-09-03)
Bug Fixes
v7.4.5Compare Source
v7.4.4Compare Source
v7.4.3Compare Source
v7.4.2Compare Source
v7.4.1Compare Source
v7.4.0Compare Source
Features
image.e12ab567.jpg) (5ed629d)Cache-Controlheader (#1923) (f7529c3)Bug Fixes
devServer: false(b443f4d)v7.3.0Compare Source
Features
7.2.1 (2024-04-02)
Bug Fixes
v7.2.1Compare Source
Features
7.2.1 (2024-04-02)
Bug Fixes
v7.2.0Compare Source
Features
7.2.1 (2024-04-02)
Bug Fixes
v7.1.1Compare Source
Features
ETagheader generation (#1797) (b759181)Last-Modifiedheader generation (#1798) (18e5683)7.1.1 (2024-03-21)
Bug Fixes
ContentLengthincorrectly set for empty files (#1785) (0f3e25e)v7.1.0Compare Source
Features
ETagheader generation (#1797) (b759181)Last-Modifiedheader generation (#1798) (18e5683)7.1.1 (2024-03-21)
Bug Fixes
ContentLengthincorrectly set for empty files (#1785) (0f3e25e)v7.0.0Compare Source
⚠ BREAKING CHANGES
Features
updated memfs@4 (#1693) (244d9f8)
minimum supported Node.js version is 18.12.0 (#1694) (e273d61)
6.1.1 (2023-05-16)
Bug Fixes
methodsshould be string array (#1550) (41b2f77)v6.1.3Compare Source
6.1.3 (2024-03-29)
Bug Fixes
v6.1.2Compare Source
6.1.2 (2024-03-20)
Bug Fixes
v6.1.1Compare Source
⚠ BREAKING CHANGES
Features
updated memfs@4 (#1693) (244d9f8)
minimum supported Node.js version is 18.12.0 (#1694) (e273d61)
6.1.1 (2023-05-16)
Bug Fixes
methodsshould be string array (#1550) (41b2f77)v6.1.0Compare Source
⚠ BREAKING CHANGES
Features
updated memfs@4 (#1693) (244d9f8)
minimum supported Node.js version is 18.12.0 (#1694) (e273d61)
6.1.1 (2023-05-16)
Bug Fixes
methodsshould be string array (#1550) (41b2f77)v6.0.2Compare Source
Features
mimeTypeDefaultoption (#1527) (503d290)modifyResponseDataoption (#1529) (35dac70)Bug Fixes
memory-fswhenwriteToDiskistrue(#1537) (852245e)6.0.2 (2023-03-19)
Bug Fixes
6.0.1 (2022-11-28)
Bug Fixes
indexandmethodsproperties (#1397) (cda328e)v6.0.1Compare Source
Features
mimeTypeDefaultoption (#1527) (503d290)modifyResponseDataoption (#1529) (35dac70)Bug Fixes
memory-fswhenwriteToDiskistrue(#1537) (852245e)6.0.2 (2023-03-19)
Bug Fixes
6.0.1 (2022-11-28)
Bug Fixes
indexandmethodsproperties (#1397) (cda328e)v6.0.0Compare Source
Features
mimeTypeDefaultoption (#1527) (503d290)modifyResponseDataoption (#1529) (35dac70)Bug Fixes
memory-fswhenwriteToDiskistrue(#1537) (852245e)6.0.2 (2023-03-19)
Bug Fixes
6.0.1 (2022-11-28)
Bug Fixes
indexandmethodsproperties (#1397) (cda328e)v5.3.4Compare Source
5.3.4 (2024-03-20)
Bug Fixes
v5.3.3Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.2Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.1Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.3.0Compare Source
⚠ BREAKING CHANGES
5.3.3 (2022-05-18)
Bug Fixes
RequestandResponse(#1271) (eeb8aa8)5.3.2 (2022-05-17)
Bug Fixes
5.3.1 (2022-02-01)
Bug Fixes
v5.2.2Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.2.1Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.2.0Compare Source
Features
5.2.2 (2021-11-17)
Chore
schema-utilspackage to4.0.0version5.2.1 (2021-09-25)
v5.1.0Compare Source
Features
Rangeheader is present (e8b21f0)Bug Fixes
mempackage (#1027) (0d55268)v5.0.0Compare Source
⚠ BREAKING CHANGES
Node.jsversion is12.13.0(#928) (4cffeff)v4.3.0Compare Source
Features
getFilenameFromUrlto API (#911) (1edc726)Bug Fixes
v4.2.0Compare Source
Features
headersoption to accept function (#897) (966afb3)v4.1.0Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.4Compare Source
Features
statsoption (376cdba)4.0.4 (2021-01-13)
Bug Fixes
4.0.3 (2021-01-12)
Bug Fixes
statstostdoutinsteadstderr, how doeswebpack-cli, if you need hidestatsfrom output please use{ stats: false }or{ stats: 'none' }(4de0f97)stats(4de0f97)Content-type headeron unknown types (#809) (5c9eee5)4.0.2 (2020-11-10)
Bug Fixes
headersoption (#763) (7c4cac5)4.0.1 (2020-11-09)
Bug Fixes
connect(b83a1db)v4.0.3Compare Source
Features
statsoption ([376cdba]Configuration
📅 Schedule: (in timezone US/Eastern)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.