VYPR

Loader Utils

by Webpack

Source repositories

CVEs (3)

  • CVE-2022-37601CriOct 12, 2022
    risk 0.57cvss 9.8epss 0.03

    Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.

  • CVE-2022-37603HigOct 14, 2022
    risk 0.42cvss 7.5epss 0.02

    A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

  • CVE-2022-37599HigOct 11, 2022
    risk 0.42cvss 7.5epss 0.02

    A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.