{"id":"DEBIAN-CVE-2025-68157","details":"Webpack is a module bundler. From version 5.49.0 to before 5.104.0, when experiments.buildHttp is enabled, webpack’s HTTP(S) resolver (HttpUriPlugin) enforces allowedUris only for the initial URL, but does not re-validate allowedUris after following HTTP 30x redirects. As a result, an import that appears restricted to a trusted allow-list can be redirected to HTTP(S) URLs outside the allow-list. This is a policy/allow-list bypass that enables build-time SSRF behavior (requests from the build machine to internal-only endpoints, depending on network access) and untrusted content inclusion in build outputs (redirected content is treated as module source and bundled). This issue has been patched in version 5.104.0.","modified":"2026-09-01T16:06:21.821237971Z","published":"2026-02-05T23:15:53.777Z","upstream":["CVE-2025-68157"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-68157"}],"affected":[{"package":{"name":"node-webpack","ecosystem":"Debian:12","purl":"pkg:deb/debian/node-webpack?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.105.4+dfsg1+~cs15.13.23-1","5.105.4+dfsg1+~cs15.13.23-2","5.105.4+dfsg1+~cs15.13.23-3","5.106.2+dfsg1+~cs15.15.23-1","5.106.2+dfsg1+~cs15.15.23-2","5.106.2+dfsg1+~cs15.15.23-3","5.107.2+dfsg1+~cs15.16.25-1","5.107.2+dfsg1+~cs15.16.25-1.1","5.107.2+dfsg1+~cs15.16.25-2","5.108.0+dfsg1+~cs14.7.20-1","5.108.0+dfsg1+~cs14.7.20-2","5.108.0+dfsg1+~cs14.7.20-3","5.75.0+dfsg+~cs17.16.14-1","5.75.0+dfsg+~cs17.16.14-1+deb12u1","5.76.1+dfsg1+~cs17.16.16-1","5.76.1+dfsg2+~cs10.8.15-2","5.76.1+dfsg2+~cs10.8.15-3","5.94.0+dfsg1+~cs11.18.26-1","5.94.0+dfsg1+~cs11.18.26-2","5.95.0+dfsg1+~cs11.18.26-1","5.96.1+dfsg1+~cs11.18.26-1","5.97.1+dfsg1+~cs11.18.27-1","5.97.1+dfsg1+~cs11.18.27-2","5.97.1+dfsg1+~cs11.18.27-3","5.97.1+dfsg1+~cs11.18.27-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68157.json"}},{"package":{"name":"node-webpack","ecosystem":"Debian:13","purl":"pkg:deb/debian/node-webpack?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.105.4+dfsg1+~cs15.13.23-1","5.105.4+dfsg1+~cs15.13.23-2","5.105.4+dfsg1+~cs15.13.23-3","5.106.2+dfsg1+~cs15.15.23-1","5.106.2+dfsg1+~cs15.15.23-2","5.106.2+dfsg1+~cs15.15.23-3","5.107.2+dfsg1+~cs15.16.25-1","5.107.2+dfsg1+~cs15.16.25-1.1","5.107.2+dfsg1+~cs15.16.25-2","5.108.0+dfsg1+~cs14.7.20-1","5.108.0+dfsg1+~cs14.7.20-2","5.108.0+dfsg1+~cs14.7.20-3","5.97.1+dfsg1+~cs11.18.27-3","5.97.1+dfsg1+~cs11.18.27-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68157.json"}},{"package":{"name":"node-webpack","ecosystem":"Debian:14","purl":"pkg:deb/debian/node-webpack?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.105.4+dfsg1+~cs15.13.23-2"}]}],"versions":["5.105.4+dfsg1+~cs15.13.23-1","5.97.1+dfsg1+~cs11.18.27-3","5.97.1+dfsg1+~cs11.18.27-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-68157.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N"}]}