Executive brief
loader-utils is a webpack utility library used to process and transform file paths and resource names during the build process. A maliciously crafted file path or resource name can trigger a Regular Expression Denial of Service (ReDoS) attack, causing the build process to hang or consume excessive CPU resources, effectively stopping builds and disrupting development workflows.
Technical details
A ReDoS vulnerability exists in the interpolateName function in interpolateName.js, where an unsafe regular expression is used to process the resourcePath variable. An attacker can craft a specially-formed resource path string that causes catastrophic backtracking in the regex engine, resulting in denial of service. The attack is network-reachable if the loader-utils library is used in a context that processes untrusted file paths (e.g., web-based build systems or dynamically-generated webpack configurations). The vulnerability affects versions 1.0.0–1.4.1, 2.0.0–2.0.3, and 3.0.0–3.2.0, and has been patched in versions 1.4.2, 2.0.4, and 3.2.1.
Affected products
- webpack loader-utils 1.0.0 to 1.4.1, 2.0.0 to 2.0.3, 3.0.0 to 3.2.0
Timeline
- 2022-10-12: disclosed
- 2022-10-12: patched: Patched in versions 1.4.2, 2.0.4, and 3.2.1