Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-37601

32
FAUCET Score

CVE-2022-37601 is a critical prototype pollution vulnerability found in the parseQuery function within webpack's loader-utils library, affecting all versions prior to 1.4.1 and 2.0.3, as well as Debian distributions utilizing these components. With a CVSS score of 9.8, this flaw allows for unauthenticated, low-complexity attacks that can lead to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.4.1CPE matchmatch criteria
cpe:2.3:a:webpack.js:loader-utils:*:*:*:*:*:*:*:*
>= 2.0.0, < 2.0.3CPE matchmatch criteria
cpe:2.3:a:webpack.js:loader-utils:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.67%
Probability of exploitation in next 30 days
EPSS Percentile
84.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0267 is in the 75th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (29)

bitdefenderpatch availablevia llm_extracted
Fixed in: ['8.2.12', '9.0.6', '9.1.1']
View patch
microsoftpatch availablevia msrc
Product: cbl2 reaper 3.1.1-3 on CBL Mariner 2.0Fixed in: 3.1.1-3
microsoftpatch availablevia msrc
Product: 19504-16823Fixed in: 3.1.1-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.1.1-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.1.1-3
npmpatch availablevia ghsa
Product: loader-utilsFixed in: 2.0.3
npmpatch availablevia ghsa
Product: loader-utilsFixed in: 1.4.1
redhatpatch availablevia redhat_api
Product: MTA-6.0-RHEL-8Fixed in: mta/mta-ui-rhel8:6.0.1-10
View patch
redhatpatch availablevia redhat_api
Product: RHOL-5.6-RHEL-8Fixed in: openshift-logging/logging-view-plugin-rhel8:v5.6.0-28
View patch
zimbrapatch availablevia llm_extracted
Fixed in: 7.3.0, 7.2.0, 7.1.2
redhatvendor investigatingvia redhat_api
Product: Migration Toolkit for VirtualizationFixed in: migration-toolkit-virtualization/mtv-ui-rhel8
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatno patchvia redhat_api
Product: Red Hat Discovery 1Fixed in: discovery-server-container
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/dashboard-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-all-in-one-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift GitOpsFixed in: openshift-gitops-1/argocd-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift Virtualization 4Fixed in: container-native-virtualization/kubevirt-console-plugin
redhatend of lifevia redhat_api
Product: OpenShift Developer Tools and ServicesFixed in: odo
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces-theia-rhel8-container
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pcs
redhatend of lifevia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-query-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: 389-ds:1.4/389-ds-base
redhatend of lifevia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: grafana
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pcs
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console
redhatend of lifevia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-console-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-multicluster-console-rhel8

Vendor Advisories (6)

zimbrallm-zimbra-abc84543908637f4CRITICAL

Splunk Enterprise Security (ES) Third-Party Package Updates - January 2024

Jan 9, 2024
bitdefenderllm-bitdefender-2250a01bd7a7224eHIGH

August 2023 Third Party Package Updates in Splunk Enterprise

Aug 30, 2023
microsoft2023-Apr/CVE-2022-37601

CVE-2022-37601

Apr 11, 2023
redhatCVE-2022-37601Important

loader-utils: prototype pollution in function parseQuery in parseQuery.js

Oct 14, 2022
npmGHSA-76p3-8jx3-jpfqcritical

Prototype pollution in webpack loader-utils

Oct 13, 2022
microsoft2022-Oct/CVE-2022-37601Critical

Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

Oct 11, 2022

References

dl.acm.org / doi/abs/10.1145/3488932.3497769
Technical Description
dl.acm.org / doi/pdf/10.1145/3488932.3497769
Technical Description
github.com / webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js
Product
github.com / webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js
Product
github.com / webpack/loader-utils/issues/212
Issue TrackingThird Party Advisory
github.com / webpack/loader-utils/issues/212
ExploitIssue TrackingThird Party Advisory
github.com / xmldom/xmldom/issues/436
ExploitIssue TrackingThird Party Advisory
lists.debian.org / debian-lts-announce/2022/12/msg00044.html
Third Party Advisory
users.encs.concordia.ca / ~mmannan/publications/JS-vulnerability-aisaccs2022.pdf
Technical Description