{"id":"CGA-h2f2-ffcm-262j","modified":"2026-09-04T22:18:28.200098462Z","published":"2026-08-24T23:24:21Z","upstream":["CVE-2025-30360","GHSA-9jgg-88mc-972h"],"references":[{"type":"WEB","url":"https://github.com/webpack/webpack-dev-server/blob/55220a800ba4e30dbde2d98785ecf4c80b32f711/lib/Server.js#L3113-L3127"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30360.json"},{"type":"ADVISORY","url":"https://github.com/webpack/webpack-dev-server/security/advisories/GHSA-9jgg-88mc-972h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-30360"},{"type":"FIX","url":"https://github.com/webpack/webpack-dev-server/commit/5c9378bb01276357d7af208a0856ca2163db188e"},{"type":"FIX","url":"https://github.com/webpack/webpack-dev-server/commit/72efaab83381a0e1c4914adf401cbd210b7de7eb"}],"affected":[{"package":{"name":"gitlab-rails-ce-fips-19.3","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/gitlab-rails-ce-fips-19.3?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.3.1-r3"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2026-09-04T14:52:50Z","component_name":"webpack-dev-server","component_version":"4.15.2","component_type":"npm","component_location":"/srv/gitlab/yarn.lock","component_purl":"pkg:npm/webpack-dev-server@4.15.2","latest_event_status":"fixed"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-h2f2-ffcm-262j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"}]}