CVE-2026-76844
Deferred
Deferred - Pending Action
Path Traversal in webpack-dev-middleware
Vulnerability report for CVE-2026-76844, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-24
Last updated on: 2026-10-01
Assigner: VulnCheck
Description
Description
zlib 1.2.11 through 1.3.2 contains a heap buffer overflow: after an underlying write() fails, gz_write() returns without resetting strm.next_in, leaving it pointed at the caller's buffer. A later gz* write call then derives a position from the stale pointer and writes past a heap allocation; any write() failure reaches it, including EPIPE on a blocking descriptor, and in versions before 1.3.1.2 the failed write must be followed by a gzclearerr() call.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| webpack | webpack-dev-middleware | From 5.3.4 (inc) |
| webpack | webpack-dev-middleware | From 6.1.2 (inc) |
| webpack | webpack-dev-middleware | From 7.1.0 (inc) |
| webpack | webpack-dev-middleware | to 5.3.3 (inc) |
| webpack | webpack-dev-middleware | 5.3.4 |
| webpack | webpack-dev-middleware | to 6.1.1 (inc) |
| webpack | webpack-dev-middleware | 6.1.2 |
| webpack | webpack-dev-middleware | to 7.0.9 (inc) |
| webpack | webpack-dev-middleware | 7.1.0 |
| webpack | webpack-dev-middleware | to 8.1.1 (exc) |
| webpack | webpack-dev-middleware | 8.1.1 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |