Skip to content
VulniPulse
Medium4.7Red Hat Linux

Medium [CVE-2026-14620] Arbitrary file opening and denial of service via exposed developer endpoints

This medium-severity Red Hat Linux advisory covers CVE-2026-14620 affecting Cryostat 4, Gatekeeper 3, Migration Toolkit for Containers.

CVE-2026-14620 Published Jul 3, 2026Updated by vendor Jul 3, 2026
Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page.

Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the

An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer's machine. Patches: upgrade to webpack-dev-server 5.2.6.

Workarounds: none. This vulnerability allows a remote attacker to exploit exposed internal developer endpoints, `/webpack-dev-server/open-editor` and `/webpack-dev-server/invalidate`, through cross-origin requests.

Repeated exploitation can lead to a denial of service by spawning numerous editor processes and forcing recompilations, degrading the developer's system performance. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L).

Weakness: CWE-940.

Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; and 24 more.

Affected versions
  • 5.2.5

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Fixed versions
  • 5.2.6

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Official advisory · high-confidence parse· fetched 12 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.