CVE-2023-26116
MEDIUMangularjs 1.2.21-1.8.2 - Regular Expression Denial of Service via angular.copy()
Title source: llmDescription
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
References (8)
Core 8
Core References
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/
Exploit, Third Party Advisory
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406320
Exploit, Third Party Advisory
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406322
Exploit, Third Party Advisory
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406321
Exploit, Third Party Advisory
https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373044
Exploit, Third Party Advisory
https://stackblitz.com/edit/angularjs-vulnerability-angular-copy-redos
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/
Scores
CVSS v3
5.3
EPSS
0.0169
EPSS Percentile
74.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1333
Status
published
Products (3)
angularjs/angularjs
1.2.21 - 1.8.3
fedoraproject/fedora
38
npm/angular
0npm
Published
Mar 30, 2023
Tracked Since
Feb 18, 2026