localhost:5173 / server-options-by-version
What changed for the Vite dev server in Vite 5, 6, 7 and 8
The change most likely to break a dev server on localhost:5173 did not arrive with a major version: Vite 4.5.6, 5.4.12 and 6.0.9, all released on 20 January 2025, added the host check behind server.allowedHosts and switched server.cors off by default.
Why a config can break without a major upgrade
The host check and the stricter CORS default were security fixes (advisory GHSA-vg6x-rcgg-rjx6) and were backported to three release lines on the same day. A caret range such as "vite": "^5.0.0" picks them up on the next install, so a project can start rejecting requests without anyone touching package.json. One day later, 4.5.9, 5.4.14 and 6.0.11 relaxed the CORS part again to allow loopback origins — which is the default the docs show today.
- 20 January 2025 — 4.5.6, 5.4.12, 6.0.9: Host header checked against server.allowedHosts; server.cors defaults to false.
- 21 January 2025 — 4.5.9, 5.4.14, 6.0.11: CORS from localhost, 127.0.0.1 and ::1 allowed by default.
- Symptom of the first change: "Blocked request. This host is not allowed." on any custom hostname or tunnel. Explained on /allowed-hosts/.
- Symptom of the second: a page on another port that fetched from 5173 before the upgrade gets a CORS error after it. Explained on /vite-cors/.
What Vite 5 changed for the dev server
Released 16 November 2023. Three changes touch the server on 5173 directly; the rest of the migration guide is about the build.
- The --https flag and https: true are gone. Since Vite 3 dropped automatic certificate generation, they only started an HTTPS server without a certificate. The server.https options object stays; plugins such as @vitejs/plugin-basic-ssl set it for you. Explained on /vite-https/.
- Terminal shortcuts need Enter: r followed by Enter restarts the server, where a single r used to be enough.
- server.middlewareMode no longer accepts "ssr" or "html". Use appType together with middlewareMode: true.
- Node.js 18 or 20+ required; 14, 16, 17 and 19 dropped.
What Vite 6 changed for the dev server
Released 26 November 2024. Most of the release is the Environment API, which the migration guide says should only affect frameworks and tools. Two points reach an ordinary vite.config.js.
- server.proxy[path].bypass is now also called for WebSocket upgrade requests, and in that call res is undefined. A bypass function that writes to res without checking throws on the first socket connection. Explained on /proxy-websocket/.
- server.fs.cachedChecks is removed. It was an opt-in optimisation that misbehaved when a file was written into a cached folder and imported immediately.
- Since 6.1.0 the environment variable __VITE_ADDITIONAL_SERVER_ALLOWED_HOSTS adds hosts to the allowed list without editing the config; since 8.1.0 it takes several hosts separated by commas.
What Vite 7 changed for the dev server
Released 24 June 2025. The shortest migration guide of the four, and nearly all of it is about the build target and removed plugin APIs.
- Node.js 20.19+ or 22.12+ required; Node 18 dropped. On an older Node the dev server is not supported at all, so no setting under server fixes it. Explained on /npm-run-dev/.
- Some internal middlewares now run before the configureServer hook. A route added by a plugin can therefore carry the headers set by server.cors; if that route should not, the plugin has to remove them.
What Vite 8 changed, and what 8.1 renamed
Released 12 March 2026. The dependency optimizer moved from esbuild to Rolldown (see /optimize-deps/). For the server itself the release added options rather than changing defaults — with one rename in a minor release that older configs do not show.
- server.forwardConsole is new in 8.0.0. Default auto: on when an AI coding agent is detected, otherwise off. It prints browser errors in the terminal that runs the dev server.
- Also in 8.0.0: before binding, the dev server checks the wildcard addresses for a conflict on the same port. See /port-in-use/.
- Vite 8.1.0, 23 June 2026: the WebSocket options of server.hmr (protocol, host, port, path, clientPort, timeout, server) moved to server.ws. The old keys are deprecated, not removed; the docs state both are synced, so the old form keeps working. Explained on /vite-hmr/.
// written for Vite 5 to 8.0 server: { hmr: { clientPort: 443 }, } // current form, Vite 8.1 and later server: { ws: { clientPort: 443 }, }
How to date a config you found somewhere else
Read the installed version first, not the one in package.json — a caret range tells you the floor, not what is in node_modules. Then compare the snippet against the dates above.
- Uses https: true or --https: written for Vite 4 or earlier.
- Has no allowedHosts but reaches the server through a custom hostname: written before 20 January 2025.
- Sets cors: true so a page on another local port can fetch from 5173: since 21 January 2025 localhost, 127.0.0.1 and ::1 are allowed by default, so this opens the server wider than needed.
- Sets WebSocket options under server.hmr: written before Vite 8.1. Still works, but the current key is server.ws.
$ npx vite --version # the version that actually starts on 5173 $ npm ls vite # the resolved version, including copies pulled in by a framework
# faq
Questions
Which Vite version introduced server.allowedHosts?
Three at once: 4.5.6, 5.4.12 and 6.0.9, all released on 20 January 2025 as a security fix. It is not tied to a major version.
Did the default of server.cors change?
Twice within two days. On 20 January 2025 it became false; on 21 January 2025 (4.5.9, 5.4.14, 6.0.11) loopback origins — localhost, 127.0.0.1 and ::1 — were allowed again by default.
Is server.hmr removed in Vite 8?
No. Since 8.1.0 its WebSocket options are deprecated in favour of server.ws, and the two are synced automatically. server.hmr itself still takes a boolean or the overlay setting.
Why does vite --https no longer work?
The flag was removed in Vite 5. It only started an HTTPS server without a certificate, because automatic certificate generation had been dropped in Vite 3. Set server.https to an options object or use a certificate plugin.
Which Node.js version does the current dev server need?
Vite 7 and later require Node.js 20.19+ or 22.12+. Vite 5 and 6 required Node.js 18 or 20+.
# next
Related
# sources
- Vite 5 — Migration from v4
- Vite 6 — Migration from v5
- Vite 7 — Migration from v6
- Vite 8 — Migration from v7
- Vite changelog (v8.3.1), including 6.0.9, 6.0.11, 6.1.0, 8.0.0 and 8.1.0
- Vite changelog (v5.4.20), including 5.4.12 and 5.4.14
- Vite security advisory GHSA-vg6x-rcgg-rjx6
- Vite — Server Options
Checked against the Vite documentation on 2026-09-29.