CVE-2022-37601
published 2022-10-12CVE-2022-37601: Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all…
PriorityP351critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.67%
84.3th percentile
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | node-loader-utils | < node-loader-utils 2.0.3-1 (bookworm) | node-loader-utils 2.0.3-1 (bookworm) |
| msrc | cbl2_reaper_3.1.1-3_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| webpack.js | loader-utils | < 1.4.1 | 1.4.1 |
| webpack.js | loader-utils | >= 0 < 1.4.1 | 1.4.1 |
| webpack.js | loader-utils | >= 2.0.0 < 2.0.3 | 2.0.3 |
| webpack.js | loader-utils | >= 2.0.0 < 2.0.3 | 2.0.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Prototype pollution occurs in the `parseQuery` function within `parseQuery.js` in the webpack loader-utils package; monitor for unexpected `__proto__` or `constructor` property manipulation via the `name` variable in query string parsing ↗
- →Exploitation of this vulnerability can lead to denial of service or remote code execution; alert on anomalous Node.js process behavior in applications using loader-utils versions prior to 1.4.1 or 2.0.3 ↗
- →Track the specific GitHub issue thread for PoC or exploit discussion related to this vulnerability ↗
- ·All versions of loader-utils prior to 1.4.1 and 2.0.3 are affected; loader-utils prior to version 3 is deprecated and no longer supported ↗
- ·In Red Hat products, loader-utils is used as a transitive dependency, reducing direct exploitability; however several container/platform packages remain affected or deferred ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Prototype pollution in webpack loader-utils
ghsa·2022-10-13
CVE-2022-37601 [CRITICAL] CWE-1321 Prototype pollution in webpack loader-utils
Prototype pollution in webpack loader-utils
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.
OSV
Prototype pollution in webpack loader-utils
osv·2022-10-13
CVE-2022-37601 [CRITICAL] Prototype pollution in webpack loader-utils
Prototype pollution in webpack loader-utils
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils prior to version 2.0.3 via the name variable in parseQuery.js.
OSV
CVE-2022-37601: Prototype pollution vulnerability in function parseQuery in parseQuery
osv·2022-10-12·CVSS 9.8
CVE-2022-37601 [CRITICAL] CVE-2022-37601: Prototype pollution vulnerability in function parseQuery in parseQuery
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Red Hat
loader-utils: prototype pollution in function parseQuery in parseQuery.js
vendor_redhat·2022-10-14·CVSS 9.8
CVE-2022-37601 [CRITICAL] CWE-1321 loader-utils: prototype pollution in function parseQuery in parseQuery.js
loader-utils: prototype pollution in function parseQuery in parseQuery.js
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
A prototype pollution vulnerability was found in the parseQuery function in parseQuery.js in the webpack loader-utils via the name variable in parseQuery.js. This flaw can lead to a denial of service or remote code execution.
Statement: Packages shipped in Red Hat Enterprise Linux use 'loader-utils' as a transitive dependency. Thus, reducing the impact to Moderate.
In Red Hat containerized products like OCP and ODF, the vulnerable loader-utils NodeJS module is bundled as a transitive dependency, hence the direct impact is reduc
Microsoft
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
vendor_msrc·2022-10-11·CVSS 9.8
CVE-2022-37601 [CRITICAL] CWE-1321 Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to ref
Debian
CVE-2022-37601: node-loader-utils - Prototype pollution vulnerability in function parseQuery in parseQuery.js in web...
vendor_debian·2022·CVSS 9.8
CVE-2022-37601 [CRITICAL] CVE-2022-37601: node-loader-utils - Prototype pollution vulnerability in function parseQuery in parseQuery.js in web...
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
Scope: local
bookworm: resolved (fixed in 2.0.3-1)
bullseye: resolved (fixed in 2.0.0-1+deb11u1)
forky: resolved (fixed in 2.0.3-1)
sid: resolved (fixed in 2.0.3-1)
trixie: resolved (fixed in 2.0.3-1)
No detection rules found.
No public exploits indexed.
http://users.encs.concordia.ca/~mmannan/publications/JS-vulnerability-aisaccs2022.pdfhttps://dl.acm.org/doi/abs/10.1145/3488932.3497769https://dl.acm.org/doi/pdf/10.1145/3488932.3497769https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L11https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L47https://github.com/webpack/loader-utils/issues/212https://github.com/webpack/loader-utils/issues/212#issuecomment-1319192884https://github.com/xmldom/xmldom/issues/436#issuecomment-1319412826https://lists.debian.org/debian-lts-announce/2022/12/msg00044.htmlhttp://users.encs.concordia.ca/~mmannan/publications/JS-vulnerability-aisaccs2022.pdfhttps://dl.acm.org/doi/abs/10.1145/3488932.3497769https://dl.acm.org/doi/pdf/10.1145/3488932.3497769https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L11https://github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/parseQuery.js#L47https://github.com/webpack/loader-utils/issues/212https://github.com/webpack/loader-utils/issues/212#issuecomment-1319192884https://github.com/xmldom/xmldom/issues/436#issuecomment-1319412826https://lists.debian.org/debian-lts-announce/2022/12/msg00044.html
2022-10-12
Published