CVE-2023-26116

MEDIUM

Angular <1.2.21 - ReDoS

Title source: llm
STIX 2.1

Description

Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

Scores

CVSS v3 5.3
EPSS 0.0032
EPSS Percentile 54.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (3)
angularjs/angularjs 1.2.21 - 1.8.3
fedoraproject/fedora 38
npm/angular 0npm
Published Mar 30, 2023
Tracked Since Feb 18, 2026