CVE-2026-6402
mediumCVSS v3 Base Score
5.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.0%
Exploitation probability in 30 days
Top 91% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
None
Availability
None
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in webpack-dev-server. When the development server operates over plain HTTP, a remote attacker can exploit a cross-origin source code exposure vulnerability. This allows a malicious website, visited by a developer, to load the bundled application source code as a script and read it across origins. Consequently, this could lead to the disclosure of sensitive application source code.
CWE
CWE-346Affected Products
Cryostat 4Gatekeeper 3Migration Toolkit for ContainersNode HealthCheck OperatorOpenShift LightspeedOpenShift PipelinesOpenShift Service Mesh 2OpenShift Service Mesh 3Red Hat AMQ Broker 7Red Hat Ansible Automation Platform 2