Medium [CVE-2026-14620] Arbitrary file opening and denial of service via exposed developer endpoints
This medium-severity Red Hat Linux advisory covers CVE-2026-14620 affecting Cryostat 4, Gatekeeper 3, Migration Toolkit for Containers.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
webpack-dev-server versions 5.2.5 and earlier expose two internal developer endpoints, /webpack-dev-server/open-editor and /webpack-dev-server/invalidate, that perform state-changing actions on any GET request without verifying that the request originated from the dev server's own page.
Any website a developer visits while the dev server is running can trigger these endpoints cross-origin with no interaction beyond the
An attacker can open an arbitrary existing local file in the developer's editor, including files outside the project root, and repeated requests can spawn editor processes and force recompilations that degrade the developer's machine. Patches: upgrade to webpack-dev-server 5.2.6.
Workarounds: none. This vulnerability allows a remote attacker to exploit exposed internal developer endpoints, `/webpack-dev-server/open-editor` and `/webpack-dev-server/invalidate`, through cross-origin requests.
Repeated exploitation can lead to a denial of service by spawning numerous editor processes and forcing recompilations, degrading the developer's system performance. Red Hat severity: Moderate — CVSS 4.7 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:L).
Weakness: CWE-940.
Affected products named by the advisory: Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; Node HealthCheck Operator; and 24 more.
- 5.2.5
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Mitigation checklist
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Official advisory · high-confidence parse· fetched 12 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.