loader-utils is vulnerable to Regular Expression Denial Of Service (ReDoS). The vulnerability is due to insecure regular expression in the url
variable of the interpolateName
function in interpolateName.js
. A remote attacker can cause denial of service via malicious regex.
github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js#L107
github.com/webpack/loader-utils/blob/d9f4e23cf411d8556f8bac2d3bf05a6e0103b568/lib/interpolateName.js#L38
github.com/webpack/loader-utils/blob/v2.0.2/lib/interpolateName.js#L107
github.com/webpack/loader-utils/commit/862ea7d1d0226558f2750bec36da02492d1e516d
github.com/webpack/loader-utils/issues/213
github.com/webpack/loader-utils/pull/157
github.com/webpack/loader-utils/pull/190
lists.fedoraproject.org/archives/list/[email protected]/message/ERN6YE3DS7NBW7UH44SCJBMNC2NWQ7SM/
lists.fedoraproject.org/archives/list/[email protected]/message/KAC5KQ2SEWAMQ6UZAUBZ5KXKEOESH375/
lists.fedoraproject.org/archives/list/[email protected]/message/VNV2GNZXOTEDAJRFH3ZYWRUBGIVL7BSU/