Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-37599

25
FAUCET Score

CVE-2022-37599 is a Regular expression Denial of Service (ReDoS) vulnerability affecting webpack loader-utils version 2.0.0. This flaw, specifically in the interpolateName function, can be triggered via the resourcePath variable. With a CVSS score of 7.5 (High), it presents a network-based attack with low complexity, requiring no user interaction, and leading to high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.4.2CPE matchmatch criteria
cpe:2.3:a:webpack.js:loader-utils:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.0.4CPE matchmatch criteria
cpe:2.3:a:webpack.js:loader-utils:*:*:*:*:*:*:*:*
>= 3.0.0, < 3.2.1CPE matchmatch criteria
cpe:2.3:a:webpack.js:loader-utils:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.13%
Probability of exploitation in next 30 days
EPSS Percentile
80.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0213 is in the 65th percentile among its peer group of 51,466 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (37)

bitdefenderpatch availablevia llm_extracted
Fixed in: ['8.2.12', '9.0.6', '9.1.1']
View patch
github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: loader-utilsFixed in: 3.2.1
npmpatch availablevia ghsa
Product: loader-utilsFixed in: 1.4.2
npmpatch availablevia ghsa
Product: loader-utilsFixed in: 2.0.4
redhatpatch availablevia redhat_api
Product: RHPAM 7.13.4 asyncFixed in: loader-utils
View patch
zimbrapatch availablevia llm_extracted
Fixed in: 7.3.0, 7.2.0, 7.1.2
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6Fixed in: loader-utils
redhatvendor investigatingvia redhat_api
Product: Red Hat Certification for Red Hat Enterprise Linux 7Fixed in: redhat-certification
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: loader-utils
redhatno patchvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-ui-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/console-plugin-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin
redhatno patchvia redhat_api
Product: Red Hat OpenShift Data Science (RHODS)Fixed in: rhods/odh-dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat Discovery 1Fixed in: discovery-server-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/traefik-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-agent-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: loader-utils
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: loader-utils
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform Expansion PackFixed in: loader-utils
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console
redhatend of lifevia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-console-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-theia-rhel8-container
redhatend of lifevia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argo-rollouts-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: loader-utils
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: servicemesh-prometheus
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: servicemesh-grafana
redhatend of lifevia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: aap-azure-ui
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: 389-ds:1.4/389-ds-base
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs

Vendor Advisories (4)

zimbrallm-zimbra-abc84543908637f4CRITICAL

Splunk Enterprise Security (ES) Third-Party Package Updates - January 2024

Jan 9, 2024
bitdefenderllm-bitdefender-2250a01bd7a7224eHIGH

August 2023 Third Party Package Updates in Splunk Enterprise

Aug 30, 2023
redhatCVE-2022-37599Moderate

loader-utils: regular expression denial of service in interpolateName.js

Oct 14, 2022
npmGHSA-hhq3-ff78-jv3ghigh

loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)

Oct 12, 2022

References

lists.fedoraproject.org / archives/list/[email protected]/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ
github.com / webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js
Third Party Advisory
github.com / webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js
Third Party Advisory
github.com / webpack/loader-utils/issues/211
Issue TrackingThird Party Advisory
github.com / webpack/loader-utils/issues/216
Issue TrackingPatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/3HUE6ZR5SL73KHL7XUPAOEL6SB7HUDT2
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/6PVVPNSAGSDS63HQ74PJ7MZ3MU5IYNVZ