CVE-2026-9595

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update

Beschreibung

Ein Fehler wurde im webpack-dev-server gefunden. Wenn ein Benutzer einen Proxy mit einem breiten Kontext konfiguriert, wie z.B. '/', und die WebSocket-Weiterleitung (ws: true) aktiviert, kann der Hot Module Replacement (HMR)-WebSocket des Entwicklungsservers abgefangen werden. Dieses Abfangen führt dazu, dass die Cookies und der Origin-Header des Browsers an das Proxy-Ziel durchsickern, wodurch die Validierung von Host/Origin auf dem Server umgangen wird. Darüber hinaus kann es den HMR-Socket beschädigen, was zu einem Denial of Service für die HMR-Funktionalität führt.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
5.3
Quelle: nvd-v3
5.8 %
Niedrig — CVE gehört zu den unteren 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-24 17:56 UTC
CWE-346, CWE-441

Weakness-Klassen (CWE)

  • CWE-346Class

    Origin Validation Error

    The product does not properly verify that the source of data or communication is valid.

    cwe.mitre.org →
  • CWE-441Class

    Unintended Proxy or Intermediary ('Confused Deputy')

    The product receives a request, message, or directive from an upstream component, but the product does not sufficiently preserve the original source of the request before forwarding the request to an external actor that is outside of the product's control sphere. This causes the product to appear to be the source of the request, leading it to act as a proxy or other intermediary between the upstream component and the external actor.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-06-16 17:24 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
    • CPE Configuration: OR *cpe:2.3:a:webpack.js:webpack-dev-server:*:*:*:*:*:*:*:* versions up to (excluding) 5.2.5
    • Reference Type: openjs: https://cna.openjsf.org/security-advisories.html Types: Vendor Advisory
    • Reference Type: openjs: https://github.com/facebook/create-react-app/pull/7444 Types: Issue Tracking, Patch
  2. New CVE Received2026-06-15 16:16 UTC· ce714d77-add3-4f53-aff5-83d477b104bb
    • Description: Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it to the proxy target. This leaks the browser's cookies and Origin header to the backend, bypasses the dev server's Host/Origin validation, and corrupts the HMR socket (both HMR and the proxy end up writing to the same socket). Patches: Fixed in webpack-dev-server@5.2.5. Workarounds: Scope user-defined proxy context to specific paths instead of /, or omit ws: true from the proxy entry when WebSocket forwarding is not required.
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
    • CWE: CWE-346
    • CWE: CWE-441

Betroffene Betriebssysteme

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / pyasn1jammy

  • linux

    ubuntu / pyasn1noble

  • linux

    ubuntu / pyasn1resolute

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • bitnami

    django6.0.0

  • djangoproject

    daphne4.2.2

  • js-cookie

    javascript_cookie3.0.7

  • npm

    tmp

  • npm

    webpack-dev-server

  • pyopenssl

    pyopenssl22.0.0 – 26.0.0

  • pypi

    aiohttp0.1

  • pypi

    aiohttp0.10.0

  • pypi

    aiohttp0.10.1

  • pypi

    aiohttp0.10.2

  • pypi

    aiohttp0.11.0

  • pypi

    aiohttp0.12.0

  • pypi

    aiohttp0.13.0

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-9595