Description
AngularJS lets users write client-side web applications. The package angular after 1.7.0 is vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ‘ ‘.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value.
Note: 1.
Recommendation
No fix is available yet. Followings are affected versions:
- >= 1.7.0
References
Could your website be exposed too?
SmartScanner can check your website for angular vulnerable to regular expression denial of service (ReDoS) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- steal vulnerable to Regular Expression Denial of Service via input variable - CVE-2022-37260
- angular vulnerable to regular expression denial of service via the angular.copy() utility - CVE-2023-26116
- Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing - CVE-2024-1899
- html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS) - CVE-2021-23346


