DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the same time uses a browser to access the internet, a malicious website they visit can use their browser to establish a cross-origin WebSocket connection to ws://127.0.0.1:8090. This vulnerability is fixed in 6.3.21.
History

Sun, 17 May 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Devspace
Devspace devspace
Vendors & Products Devspace
Devspace devspace

Sat, 16 May 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore several endpoints are exposed via this WebSocket. When a developer runs the DevSpace UI and at the same time uses a browser to access the internet, a malicious website they visit can use their browser to establish a cross-origin WebSocket connection to ws://127.0.0.1:8090. This vulnerability is fixed in 6.3.21.
Title DevSpace UI Server WebSocket CheckOrigin does not validate source
Weaknesses CWE-200
CWE-306
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-05-14T15:44:22.499Z

Updated: 2026-05-16T00:36:17.542Z

Reserved: 2026-04-26T12:13:55.551Z

Link: CVE-2026-42283

cve-icon Vulnrichment

Updated: 2026-05-16T00:36:13.103Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-14T16:16:21.347

Modified: 2026-05-14T18:12:13.527

Link: CVE-2026-42283

cve-icon Redhat

No data.