Vulnerability library
Security checkNovember 03, 2025

angular vulnerable to regular expression denial of service (ReDoS)

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmangular

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

AngularJS lets users write client-side web applications. The package angular after 1.7.0 is vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ‘ ‘.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value.

Note: 1.

Recommendation

No fix is available yet. Followings are affected versions:

  • >= 1.7.0

References

Could your website be exposed too?

SmartScanner can check your website for angular vulnerable to regular expression denial of service (ReDoS) and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated November 03, 2025