localhost:5173 / server-options-by-version

What changed for the Vite dev server in Vite 5, 6, 7 and 8

The change most likely to break a dev server on localhost:5173 did not arrive with a major version: Vite 4.5.6, 5.4.12 and 6.0.9, all released on 20 January 2025, added the host check behind server.allowedHosts and switched server.cors off by default.

Why a config can break without a major upgrade

The host check and the stricter CORS default were security fixes (advisory GHSA-vg6x-rcgg-rjx6) and were backported to three release lines on the same day. A caret range such as "vite": "^5.0.0" picks them up on the next install, so a project can start rejecting requests without anyone touching package.json. One day later, 4.5.9, 5.4.14 and 6.0.11 relaxed the CORS part again to allow loopback origins — which is the default the docs show today.

  • 20 January 2025 — 4.5.6, 5.4.12, 6.0.9: Host header checked against server.allowedHosts; server.cors defaults to false.
  • 21 January 2025 — 4.5.9, 5.4.14, 6.0.11: CORS from localhost, 127.0.0.1 and ::1 allowed by default.
  • Symptom of the first change: "Blocked request. This host is not allowed." on any custom hostname or tunnel. Explained on /allowed-hosts/.
  • Symptom of the second: a page on another port that fetched from 5173 before the upgrade gets a CORS error after it. Explained on /vite-cors/.

What Vite 5 changed for the dev server

Released 16 November 2023. Three changes touch the server on 5173 directly; the rest of the migration guide is about the build.

  • The --https flag and https: true are gone. Since Vite 3 dropped automatic certificate generation, they only started an HTTPS server without a certificate. The server.https options object stays; plugins such as @vitejs/plugin-basic-ssl set it for you. Explained on /vite-https/.
  • Terminal shortcuts need Enter: r followed by Enter restarts the server, where a single r used to be enough.
  • server.middlewareMode no longer accepts "ssr" or "html". Use appType together with middlewareMode: true.
  • Node.js 18 or 20+ required; 14, 16, 17 and 19 dropped.

What Vite 6 changed for the dev server

Released 26 November 2024. Most of the release is the Environment API, which the migration guide says should only affect frameworks and tools. Two points reach an ordinary vite.config.js.

  • server.proxy[path].bypass is now also called for WebSocket upgrade requests, and in that call res is undefined. A bypass function that writes to res without checking throws on the first socket connection. Explained on /proxy-websocket/.
  • server.fs.cachedChecks is removed. It was an opt-in optimisation that misbehaved when a file was written into a cached folder and imported immediately.
  • Since 6.1.0 the environment variable __VITE_ADDITIONAL_SERVER_ALLOWED_HOSTS adds hosts to the allowed list without editing the config; since 8.1.0 it takes several hosts separated by commas.

What Vite 7 changed for the dev server

Released 24 June 2025. The shortest migration guide of the four, and nearly all of it is about the build target and removed plugin APIs.

  • Node.js 20.19+ or 22.12+ required; Node 18 dropped. On an older Node the dev server is not supported at all, so no setting under server fixes it. Explained on /npm-run-dev/.
  • Some internal middlewares now run before the configureServer hook. A route added by a plugin can therefore carry the headers set by server.cors; if that route should not, the plugin has to remove them.

What Vite 8 changed, and what 8.1 renamed

Released 12 March 2026. The dependency optimizer moved from esbuild to Rolldown (see /optimize-deps/). For the server itself the release added options rather than changing defaults — with one rename in a minor release that older configs do not show.

  • server.forwardConsole is new in 8.0.0. Default auto: on when an AI coding agent is detected, otherwise off. It prints browser errors in the terminal that runs the dev server.
  • Also in 8.0.0: before binding, the dev server checks the wildcard addresses for a conflict on the same port. See /port-in-use/.
  • Vite 8.1.0, 23 June 2026: the WebSocket options of server.hmr (protocol, host, port, path, clientPort, timeout, server) moved to server.ws. The old keys are deprecated, not removed; the docs state both are synced, so the old form keeps working. Explained on /vite-hmr/.
vite.config.js — the same socket setting before and after 8.1
// written for Vite 5 to 8.0
server: {
  hmr: { clientPort: 443 },
}

// current form, Vite 8.1 and later
server: {
  ws: { clientPort: 443 },
}

How to date a config you found somewhere else

Read the installed version first, not the one in package.json — a caret range tells you the floor, not what is in node_modules. Then compare the snippet against the dates above.

  • Uses https: true or --https: written for Vite 4 or earlier.
  • Has no allowedHosts but reaches the server through a custom hostname: written before 20 January 2025.
  • Sets cors: true so a page on another local port can fetch from 5173: since 21 January 2025 localhost, 127.0.0.1 and ::1 are allowed by default, so this opens the server wider than needed.
  • Sets WebSocket options under server.hmr: written before Vite 8.1. Still works, but the current key is server.ws.
bash
$ npx vite --version
# the version that actually starts on 5173

$ npm ls vite
# the resolved version, including copies pulled in by a framework

# faq

Questions

Which Vite version introduced server.allowedHosts?

Three at once: 4.5.6, 5.4.12 and 6.0.9, all released on 20 January 2025 as a security fix. It is not tied to a major version.

Did the default of server.cors change?

Twice within two days. On 20 January 2025 it became false; on 21 January 2025 (4.5.9, 5.4.14, 6.0.11) loopback origins — localhost, 127.0.0.1 and ::1 — were allowed again by default.

Is server.hmr removed in Vite 8?

No. Since 8.1.0 its WebSocket options are deprecated in favour of server.ws, and the two are synced automatically. server.hmr itself still takes a boolean or the overlay setting.

Why does vite --https no longer work?

The flag was removed in Vite 5. It only started an HTTPS server without a certificate, because automatic certificate generation had been dropped in Vite 3. Set server.https to an options object or use a certificate plugin.

Which Node.js version does the current dev server need?

Vite 7 and later require Node.js 20.19+ or 22.12+. Vite 5 and 6 required Node.js 18 or 20+.

# next

Related

  • Every server option that changes what localhost:5173 doesEverything the dev server on localhost:5173 does is configured under the server key in vite.config.js — twenty options, of which only host, port, strictPort, open and cors have a CLI flag; the rest exist in the config file only.
  • Blocked request. This host is not allowed.The Vite dev server only answers to localhost, hostnames ending in .localhost, and IP addresses — every other hostname has to be listed in server.allowedHosts.
  • CORS errors around localhost:5173The Vite dev server only accepts cross-origin requests from localhost, 127.0.0.1 and ::1 by default — anything else has to be allowed explicitly, and setting cors to true opens it to every website.
  • Hot Module Replacement on localhost:5173HMR swaps a changed module in the running page over a WebSocket instead of reloading it; when that WebSocket cannot connect, Vite falls back to full page reloads or stops updating at all.
  • How every claim on this site is verifiedEvery page here is checked against one named Vite release — 8.3.0, published 2026-09-10 — in three places in a fixed order: the documentation, the source at that release tag, and a local reproduction, and the date of that check is printed at the foot of the page.
  • localhost:5173 — the port itselfWhat the address means, common dev ports, and the autocomplete fix.