← All tasks
javascriptangular/angular-cli #33903Not a task: not reproduced

Update @angular-devkit/build-angular v21/v20 dependency webpack-dev-server to 5.2.6 to mitigate GHSA-m28w-2pqf-7qgj and GHSA-f5vj-f2hx-8m93

envgap__angular__angular-cli-33903

01 / FAILURE SIGNATURE

As reported upstream

### Exception or Error
Not a benchmark task.
  • In a clean container the reported failure did not reproduce, or the known fix did not make the project run.

02 / ENVIRONMENT RECIPE

Base commit
90e805972267bd0abe464c6e842f357adc5dc1ce
Manifest
packages/angular_devkit/build_angular/package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

angular/angular-cli #33903 · read the original issue
### Command

serve, other

### Is this a regression?

- [ ] Yes, this behavior used to work in the previous version

### The previous version in which this bug was not present was

_No response_

### Description

Excerpt from the `@angular-devkit/build-angular@21` dependency tree:

```
@angular-devkit/build-angular@21.2.21
└── webpack-dev-server@5.2.5
```

`webpack-dev-server` <= 5.2.5 is affected by two advisories, both fixed in 5.2.6:

- GHSA-m28w-2pqf-7qgj (CVE-2026-14631, moderate) — denial of service: a malformed `Host` header, or a malformed `Origin` on a WebSocket upgrade to `/ws`, throws an uncaught exception in the host-validation logic and terminates the dev-server process.
- GHSA-f5vj-f2hx-8m93 (CVE-2026-14620, moderate) — CSRF: `/webpack-dev-server/open-editor` and `/webpack-dev-server/invalidate` handle GET requests without verifying the request originated from the dev server's own page, so a page a developer visits while `ng serve` is running can open arbitrary local files in their editor or force repeated recompiles.

`main` already pins `webpack-dev-server` 6.0.0 and 22.1.5 ships 5.2.6, so only the v21 and v20 lines are affected — branches `21.2.x` and `20.3.x` both pin `5.2.5`. Since the dependency is pinned to an exact version, consumers on those lines cannot pick up 5.2.6 without a package-manager override. 5.2.6 is a patch release of the already-pinned 5.2.x, so the bump should be a drop-in.

### Minimal Reproduction

- `npm view @angular-devkit/build-angular@21.2.21 dependencies.webpack-dev-server` prints `5.2.5` (same for `@20.3.34`)
- Or: install `@angular-devkit/build-angular@^21` (or `^20`) in a project and run `npm audit`

### Exception or Error

```text
Dependency webpack-dev-server@5.2.5 vulnerable to GHSA-m28w-2pqf-7qgj and GHSA-f5vj-f2hx-8m93
```

### Your Environment

```text
Node.js           : 24.19.0
Package Manager   : npm 11.17.0
Operating System  : win32 x64

Pins taken from published package metadata and from the repository branches:

@angular-devkit/build-angular@21.2.21 (v21-lts)  -> webpack-dev-server 5.2.5   affected
@angular-devkit/build-angular@20.3.34 (v20-lts)  -> webpack-dev-server 5.2.5   affected
@angular-devkit/build-angular@22.1.5  (latest)   -> webpack-dev-server 5.2.6   already fixed
branch main                                      -> webpack-dev-server 6.0.0   already fixed
```

### Anything else relevant?

`@angular/build` does not depend on `webpack-dev-server`, so this only affects projects still using the webpack-based `@angular-devkit/build-angular` builders. The sibling `webpack-dev-middleware` pin (7.4.5 on `21.2.x`) is not affected by these advisories. Similar past report for the 2025 `webpack-dev-server` CVEs: #30505.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]