CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-76844

CVE-2026-76844: Path Traversal in webpack-dev-middleware via Incomplete Prefix Validation

Amit Schendel
Amit Schendel
Senior Security Researcher

Sep 29, 2026·5 min read·9 visits

Executive Summary (TL;DR)

webpack-dev-middleware suffers from a path traversal flaw when publicPath lacks a trailing slash and physical files are served, allowing attackers to read files one directory above the output root via crafted HTTP requests like GET /assets../.env.

CVE-2026-76844 is a high-severity path traversal vulnerability in webpack-dev-middleware affecting multiple version branches. It stems from an incomplete fix for CVE-2024-29180 when serving files via a physical filesystem with a non-slash-terminated publicPath configuration. Attackers can bypass directory validation to access files situated one level above the intended output directory.

Vulnerability Overview

webpack-dev-middleware is an essential Node.js package that serves assets emitted from a Webpack compiler. It is frequently integrated within development servers like webpack-dev-server to stream assets directly to client browsers during local development cycles.

To ensure proper performance and capability, the middleware exposes an HTTP-accessible surface where requested URIs are dynamically mapped to local files. The mapping logic evaluates raw incoming paths, verifies access permissions, and handles the retrieval of output artifacts. This behavior exposes a critical attack surface if access checks are bypassed.

CVE-2026-76844 represents an incomplete remediation of CVE-2024-29180. Under specific conditions—such as a configuration lacking a trailing slash on the virtual resource path coupled with direct disk-write settings—an unauthenticated network attacker can leverage structured path requests to read local system configuration files situated above the output directory root.

Root Cause Analysis

The root cause of this vulnerability lies in the sequence of input verification and path truncation logic implemented in getFilenameFromUrl. The middleware evaluates if an incoming URI path starts with the specified virtual root directory (publicPath) and tests the raw input string against a validation regular expression (UP_PATH_REGEXP).

This regular expression only detects parent traversal sequences (..) when they are delimited as isolated directory segments (such as /../). If the double dot sequence is nested inside an arbitrary string sequence, it passes this validation check untouched.

When a publicPath is configured without a trailing slash (e.g., /assets), a request targeting /assets../.env evaluates as starting with the prefix /assets. The traversal guard examines the string /assets../.env and permits the request because the string segment assets.. does not match the standalone double-dot pattern.

Following the guard bypass, the application slices the raw path by the exact length of the publicPath prefix (7 characters). This slicing converts /assets../.env into the relative string ../.env, which is subsequently joined with the physical output path, escaping the designated asset sandbox.

Code Path Analysis

The flawed logic is located within the request-handling middleware files where output file paths are derived from URLs. Below is a representation of the vulnerable path derivation flow.

// VULNERABLE CODE PATH
const UP_PATH_REGEXP = /(?:^|[\\/])\.\.(?:[\\/]|$)/;
 
function getFilenameFromUrl(context, url) {
  const pathname = parseUrl(url);
  
  // Check if pathname starts with the public path
  if (pathname.startsWith(publicPathPathname)) {
    // Ensure the raw path has no explicit traversal sequences
    if (UP_PATH_REGEXP.test(pathname)) {
      throw new Error('Forbidden');
    }
    
    // Slicing here strips the prefix and yields relative traversal characters
    const remainder = pathname.slice(publicPathPathname.length);
    const filename = path.join(outputPath, remainder);
    return filename;
  }
}

The fundamental mitigation checks the validity of the computed absolute filepath rather than trying to sanitize the un-stripped request string. This is accomplished using path.relative to enforce folder containment boundaries.

// PATCHED IMPLEMENTATION
const filename = path.join(outputPath, pathname.slice(publicPathPathname.length));
 
// Compute path relative to the defined output root
const relative = path.relative(outputPath, filename);
 
// If the relative path points upwards (..), block the request
if (
  relative === ".." ||
  relative.startsWith(`..${path.sep}`) ||
  path.isAbsolute(relative)
) {
  throw new FilenameError("Forbidden", 403);
}

By comparing the output directory with the final resolved filename, the middleware accurately identifies if the resolved file resides outside the boundaries of the output path. This boundary enforcement renders string manipulation tricks irrelevant.

Exploitation Methodology

Exploitation of CVE-2026-76844 is direct and requires no prior authentication. However, successful retrieval of arbitrary files relies on several configuration prerequisites.

First, the virtual path prefix (publicPath) must be configured to omit a trailing slash (for example, /static instead of /static/). Second, the middleware must execute file reads against a physical disk rather than an in-memory buffer. This condition is satisfied when developers enable the writeToDisk option or pass a native physical file system as the outputFileSystem property.

An attacker sends a formatted HTTP request targeting the root path prefix followed by a double dot sequence and the target filename:

GET /static../.env HTTP/1.1
Host: target-dev-server:8080
Connection: close

Because the browser or client routing libraries collapse paths prior to server-side interpretation, the exploitation is strictly limited to reading files situated exactly one level above the compiled asset output root. Deep traversal via nested paths (e.g. ../../) is neutralized during the standard URL parsing pipeline.

Impact Assessment

This vulnerability exposes high-value intellectual property and configuration secrets stored on development machines and server nodes. Since development environments routinely hold unencrypted environment files (.env), AWS credentials, and database connection strings inside the parent project folder, a single file disclosure can lead to broader infrastructure compromise.

The vulnerability is designated a CVSS v3.1 score of 7.4 (High), with high confidentiality impact. Because the vulnerability permits directory escaping, the Scope metric is evaluated as Changed, indicating that the impact extends beyond the sandboxed memory execution environment of the webpack compilation.

Although the threat of automated internet-wide exploitation is limited by the typical localized deployments of development servers, the exploit is trivial to execute. Remote attackers targeting corporate intranets or phishing developers to execute cross-site requests can successfully exfiltrate sensitive credentials.

Remediation & Mitigation

Remediation requires upgrading the underlying dependency to a version containing the post-resolution containment check. The patch was backported and released in versions 7.4.6 and 8.3.0.

If upgrading is not an immediate option, developers can apply an effective configuration-based workaround. Modifying the publicPath property in the Webpack configuration to include a trailing slash prevents the slice bypass.

// WORKAROUND CONFIGURATION
module.exports = {
  output: {
    // Terminating with a slash isolates prefix comparisons
    publicPath: '/assets/',
  },
};

When a trailing slash is appended, a request targeting /assets../.env fails the pathname.startsWith('/assets/') validation step entirely. The middleware will not process the request as matching the public asset scope, neutralizing the traversal vector.

Official Patches

webpackV8 & V7 patch fixing path traversal containment
webpackAlternative commit implementing relative path checks

Fix Analysis (2)

Technical Appendix

CVSS Score
7.4/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
EPSS Probability
0.48%
Top 61% most exploited
1,500
via Shodan

Affected Systems

webpack-dev-middleware versions 5.3.4, 6.1.2-6.1.3, 7.1.0-7.4.5, 8.0.0-8.1.1 configured with writeToDisk or custom physical outputFileSystem

Affected Versions Detail

Product
Affected Versions
Fixed Version
webpack-dev-middleware
webpack
>= 5.3.4, <= 8.1.17.4.6, 8.3.0
AttributeDetail
CWE IDCWE-22 (Path Traversal)
Attack VectorNetwork (AV:N)
CVSS v3.17.4 (High)
EPSS Score0.00483
ImpactConfidentiality (High)
Exploit StatusProof-of-Concept (PoC)
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Known Exploits & Detection

GitHub Advisory / Patch TestsIntegration tests illustrating path resolution exploit vector using /static../ test suite cases

Vulnerability Timeline

CVE-2024-29180 initial mitigation released
2024-03-20
CVE-2026-76844 discovered as an incomplete fix bypass
2026-02-15
Vendor security advisory published and patched versions released
2026-02-18

References & Sources

  • [1]GitHub Security Advisory GHSA-wr3j-pwj9-hqq6
  • [2]webpack-dev-middleware Middleware Source File
  • [3]VulnCheck Advisory for webpack-dev-middleware
  • [4]Fix Commit 1 (v8.x/v7.x)
  • [5]Fix Commit 2
Related Vulnerabilities
CVE-2024-29180

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•37 minutes ago•CVE-2026-102279
3.1

CVE-2026-102279: DOM-based Cross-Site Scripting in Laravel Exception Debug Page via Tippy.js

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Laravel exception debug page rendering pipeline when APP_DEBUG=true is active. This flaw allows an attacker to execute arbitrary client-side JavaScript in the security context of an authenticated user's session when they hover over interactive code-trace tooltips handled by Tippy.js.

Amit Schendel
Amit Schendel
5 views•5 min read
•about 2 hours ago•GHSA-RCW4-F5RP-G42V
7.5

GHSA-RCW4-F5RP-G42V: Uncontrolled Resource Consumption and Decompression Bomb Protection Bypass in adm-zip

A critical denial-of-service vulnerability in the adm-zip npm package allows attackers to bypass decompression-bomb protections introduced in version 0.5.18. By declaring the uncompressed file size as exactly 0, an attacker can disable the maxOutputLength constraint in the Node.js zlib wrapper, leading to complete system memory exhaustion and process crashes.

Alon Barad
Alon Barad
6 views•8 min read
•about 3 hours ago•CVE-2026-81872
6.3

CVE-2026-81872: CPU Exhaustion via Tight Loop in OpenTelemetry-Go BatchingProcessor

An uncontrolled resource consumption vulnerability in the logs SDK of OpenTelemetry-Go allows remote attackers to trigger a denial of service. Under conditions of downstream exporter backpressure, the BatchingProcessor enters a tight loop, exhausting CPU resources. This occurs because the processor immediately schedules retry attempts without waiting for its ticker interval, spinning continuously when the internal queue remains filled above the batch size. The issue affects all versions prior to v0.21.0 of the go.opentelemetry.io/otel/sdk/log package.

Alon Barad
Alon Barad
9 views•7 min read
•about 11 hours ago•CVE-2026-77310
5.3

CVE-2026-77310: Server-Side Request Forgery via DNS Resolution in jackson-databind

A Server-Side Request Forgery (SSRF) vulnerability exists in FasterXML jackson-databind before versions 2.18.9, 2.21.5, 2.22.1, 3.1.5, and 3.2.1. The flaw occurs during the deserialization of java.net.InetAddress fields, where the library implicitly triggers eager DNS lookups. Unauthenticated remote attackers can exploit this behavior by passing arbitrary hostnames in JSON fields, forcing target servers to make outbound DNS lookup requests.

Alon Barad
Alon Barad
8 views•4 min read
•about 12 hours ago•CVE-2026-19032
5.3

CVE-2026-19032: Insecure Deserialization and Class Loading via java.nio.file.Path Resolution in FasterXML jackson-databind

An insecure deserialization vulnerability exists in FasterXML jackson-databind due to improper validation of URI schemes when resolving java.nio.file.Path properties. When binding untrusted JSON input to a Path field, the deserializer resolves attacker-supplied URIs without restriction. If the scheme is unrecognized by the default filesystem, the application falls back to querying registered SPI FileSystemProvider instances, causing class loading and potential side effects in environments with custom providers.

Alon Barad
Alon Barad
12 views•6 min read
•about 13 hours ago•CVE-2026-68497
7.5

CVE-2026-68497: CPU Denial of Service via XML Datatype Deserialization in FasterXML jackson-databind

CVE-2026-68497 is a high-severity CPU Denial of Service (DoS) vulnerability in jackson-databind. It arises because the library bypasses default input constraint checks when parsing stringified XML datatypes, subsequently passing arbitrary-length inputs to JDK constructors with quadratic execution complexity.

Alon Barad
Alon Barad
18 views•6 min read