A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-node-loader-utils | Jul 30, 2024 | Oct 11, 2022 | |
| Elasticpress Plugin | elasticpress-plugin-cve-2022-37599 | May 15, 2025 | Oct 11, 2022 | |
| Insert Special Characters Plugin | insert-special-characters-plugin-cve-2022-37599 | May 15, 2025 | Oct 11, 2022 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 11, 2022 |
| Restricted Site Access Plugin | restricted-site-access-plugin-cve-2022-37599 | May 15, 2025 | Oct 11, 2022 | |
| Simple Page Ordering Plugin | simple-page-ordering-plugin-cve-2022-37599 | May 15, 2025 | Oct 11, 2022 | |
| Splunk | splunk-upgrade-latest | Sep 30, 2025 | Oct 11, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub