<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T20:15:26.194708+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-68458</id>
    <title>CVE-2025-68458 — webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior</title>
    <updated>2026-10-05T20:15:26.226509+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> webpack</p>
<p>Webpack is a module bundler. From version 5.49.0 to before 5.104.1, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) can be bypassed to fetch resources from hosts outside allowedUris by using crafted URLs that include userinfo (username:password@host). If allowedUris enforcement relies on a raw string prefix check (e.g., uri.startsWith(allowed)), a URL that looks allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a policy/allow-list bypass that enables build-time SSRF behavior (outbound requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion (the fetched response is treated as module source and bundled). This issue has been patched in version 5.104.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-68458"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8fgc-7cc6-rx7x</id>
    <title>GHSA-8fgc-7cc6-rx7x — webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior</title>
    <updated>2026-10-05T20:15:26.226577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: webpack</p>
<p>### Summary
When `experiments.buildHttp` is enabled, webpack’s HTTP(S) resolver (`HttpUriPlugin`) can be bypassed to fetch resources from **hosts outside `allowedUris`** by using crafted URLs that include **userinfo** (`username:password@host`). If `allowedUris` enforcement relies on a **raw string prefix check** (e.g., `uri.startsWith(allowed)`), a URL that *looks* allow-listed can pass validation while the actual network request is sent to a different authority/host after URL parsing. This is a **policy/allow-list bypass** that enables **build-time SSRF behavior** (outbound requests from the build machine to internal-only endpoints, depending on network access) and **untrusted content inclusion** (the fetched response is treated as module source and bundled). In my reproduction, the internal response was also persisted in the buildHttp cache.</p>
<p>Reproduced on:
- webpack version: **5.104.0**
- Node version: **v18.19.1**</p>
<p>### Details
**Root cause (high level):** `allowedUris` validation can be performed on the raw URI string, while the actual request destination is determined later by parsing the URL (e.g., `new URL(uri)`), which interprets the **authority** as the part after `@`.</p>
<p>Example crafted URL:
- `http://127.0.0.1:9000@127.0.0.1:9100/secret.js`</p>
<p>If the allow-list is `["http://127.0.0.1:9000"]`, then:
- Raw string check:  
  `crafted.startsWith("http://127.0.0.1:9000")` → **true**
- URL parsing (WHAT `new URL()` will contact):  
  `origin` → `http://127.0.0.1:9100` (hos…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8fgc-7cc6-rx7x"/>
  </entry>
</feed>
