DNA View

CVE-2023-26116

Medium
Low Medium High Critical
5.3
CVSS Score
Published: Mar 30, 2023
Last Modified: Nov 20, 2025

Vulnerability Description

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
N
Integrity
N
Availability
L

Known Affected Software

1 configuration(s) from 1 vendor(s)

fedora
Version:
38
CPE:
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
This vulnerability affects 1 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

1 patch available from vendors

View All Patches
Canonical (Ubuntu)

USN-7958-1

USN-7958-1: AngularJS vulnerabilities

Severity
Unknown
Released
Jan 14, 2026
Security Update

References & Resources

Severity Details

5.3
out of 10.0
Medium

Key Information

Published Date
March 30, 2023