DNA View

CVE-2022-25844

Medium
Low Medium High Critical
5.3
CVSS Score
Published: May 01, 2022
Last Modified: Nov 20, 2025

Vulnerability Description

The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
N
Integrity
N
Availability
L

Known Affected Software

3 configuration(s) from 2 vendor(s)

fedora
Version:
35
CPE:
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
fedora
Version:
36
CPE:
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
ontap_select_deploy_administration_utility
Version:
-
CPE:
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
This vulnerability affects 3 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

1 patch available from vendors

View All Patches
Canonical (Ubuntu)

USN-7958-1

USN-7958-1: AngularJS vulnerabilities

Severity
Unknown
Released
Jan 14, 2026
Security Update

References & Resources

Severity Details

5.3
out of 10.0
Medium

Key Information

Published Date
May 01, 2022