Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-37598

31
FAUCET Score

CVE-2022-37598 is a critical prototype pollution vulnerability affecting mishoo UglifyJS versions up to 3.13.2, specifically within the DEFNODE function in ast.js. With a CVSS score of 9.8, it presents a severe risk due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While the vendor disputes its validity, there is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
3.13.2CPE matchmatch criteria
cpe:2.3:a:uglifyjs_project:uglifyjs:3.13.2:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.35%
Probability of exploitation in next 30 days
EPSS Percentile
68.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0135 is in the 55th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (16)

redhatno patchvia redhat_api
Product: Migration Toolkit for RuntimesFixed in: uglify-js
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-all-in-one-rhel8
redhatno patchvia redhat_api
Product: Red Hat OpenShift distributed tracing 2Fixed in: rhosdt/jaeger-query-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-prometheus
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.1Fixed in: servicemesh-grafana
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Management for Kubernetes 2Fixed in: rhacm2/console-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-main-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Advanced Cluster Security 3Fixed in: advanced-cluster-security/rhacs-rhel8-operator
redhatend of lifevia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: cockpit-ceph-installer
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: uglify-js
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel K 1Fixed in: uglify-js
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: openshift-service-mesh/kiali-rhel8
redhatend of lifevia redhat_api
Product: OpenShift Service Mesh 2.0Fixed in: servicemesh-grafana

Vendor Advisories (1)

redhatCVE-2022-37598Moderate

uglify-js: Prototype pollution vulnerability in function DEFNODE in ast.js

Oct 20, 2022

References

github.com / mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.js
ExploitThird Party Advisory
github.com / mishoo/UglifyJS/blob/352a944868b09c9ce3121a49d4a0bf0afe370a35/lib/ast.js
ExploitThird Party Advisory
github.com / mishoo/UglifyJS/issues/5699
Issue TrackingThird Party Advisory
github.com / mishoo/UglifyJS/issues/5721
Third Party Advisory