CVE-2023-26116
MediumVulnerability Description
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Known Affected Software
1 configuration(s) from 1 vendor(s)
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
USN-7958-1
USN-7958-1: AngularJS vulnerabilities
References & Resources
-
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/report@snyk.io Mailing List Third Party Advisory
-
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/report@snyk.io
-
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406320report@snyk.io Exploit Third Party Advisory
-
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406322report@snyk.io Exploit Third Party Advisory
-
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406321report@snyk.io Exploit Third Party Advisory
-
https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373044report@snyk.io Exploit Third Party Advisory
-
https://stackblitz.com/edit/angularjs-vulnerability-angular-copy-redosreport@snyk.io Exploit Third Party Advisory
-
https://lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlaf854a3a-2127-422b-91ae-364da2661108
-
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/af854a3a-2127-422b-91ae-364da2661108 Mailing List Third Party Advisory
-
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/af854a3a-2127-422b-91ae-364da2661108
-
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406320af854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory
-
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406322af854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory
-
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406321af854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory
-
https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373044af854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory
-
https://stackblitz.com/edit/angularjs-vulnerability-angular-copy-redosaf854a3a-2127-422b-91ae-364da2661108 Exploit Third Party Advisory
Severity Details
Key Information
- Published Date
- March 30, 2023
