CVE Explorer
CVE-2025-68458
Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/ho
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"webpack","vendor":"webpack","versions":[{"status":"affected","version":">= 5.49.0, < 5.104.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:956d97becddf22fc971fdd6f2a5c8aa8faddea1b521fed56d90ea6ec72e2035b · sha256:792514d574ae6ff3… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:956d97becddf22fc971fdd6f2a5c8aa8faddea1b521fed56d90ea6ec72e2035b · sha256:792514d574ae6ff3… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:956d97becddf22fc971fdd6f2a5c8aa8faddea1b521fed56d90ea6ec72e2035b · sha256:792514d574ae6ff3… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/webpack/webpack/security/advisories/GHSA-8fgc-7cc6-rx7x","tags":["x_refsource_CONFIRM"],"url":"https://github.com/webpack/webpack/security/advisories/GHSA-8fgc-7cc6-rx7x"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:956d97becddf22fc971fdd6f2a5c8aa8faddea1b521fed56d90ea6ec72e2035b · sha256:792514d574ae6ff3… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.