CVE-2022-37599

Aliases:GHSA-hhq3-ff78-jv3g
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 11 Oct 2022, 00:00
Last modified:04 Nov 2025, 18:14

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
4.21% LOW
4% probability +1.17%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

11 Oct 2022, 00:00
Published
Vulnerability first disclosed
04 Nov 2025, 18:14
Last Modified
Vulnerability information updated

Description

A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v3.1LOWScore: 3.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

EPSS Trends

Current EPSS score: 4.21% Percentile: 89%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • Npmloader-utils

    ≥ 1.0.0, < 1.4.2 | ≥ 2.0.0, < 2.0.4 | ≥ 3.0.0, < 3.2.1

  • webpack.jsloader-utils

    ≥ 1.0.0, < 1.4.2 | ≥ 2.0.0, < 2.0.4 | ≥ 3.0.0, < 3.2.1

  • wordpresselasticpress

    ≤ 4.3.1

  • wordpressinsert-special-characters

    ≤ 1.0.5

  • wordpressrestricted-site-access

    ≤ 7.3.4

  • wordpresssimple-page-ordering

    ≤ 2.4.3

References (16)