Regular Expression Denial of Service (ReDoS)
Published May 1, 2022
7.5
HIGHCVSS 3.1
EPSS 4.93%
Description
The package angular after 1.7.0 are vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1) This package has been deprecated and is no longer maintained. 2) The vulnerable versions are 1.7.0 and higher.
Affected products
- Vendor n/a Product Angular Defaultn/a
- Version next of 1.7.0StatusaffectedConstraints<unspecified
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Angular | n/a |
|
Configuration 2
- 35
- 36
Configuration 3
- n/a
No data.
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.1
servicemesh-grafana
Will not fix
Red Hat Ceph Storage 3
grafana
Not affected
Red Hat Ceph Storage 4
rhceph/rhceph-4-dashboard-rhel8
Not affected
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Not affected
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 7
thunderbird
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
firefox:flatpak/firefox
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
gjs
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Enterprise Linux 9
thunderbird:flatpak/thunderbird
Not affected
Red Hat Fuse 7
angular
Not affected
Red Hat JBoss Data Grid 7
angular
Not affected
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_2-eap6
Out of support scope
Red Hat OpenStack Platform 16.1
qpid-dispatch
Not affected
Red Hat OpenStack Platform 16.2
qpid-dispatch
Not affected
Red Hat Quay 3
quay/quay-rhel8
Not affected
Red Hat Satellite 6
qpid-dispatch
Will not fix
Red Hat Single Sign-On 7
keycloak-theme
Will not fix
Red Hat Storage 3
grafana
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Will not fix | n/a |
| Red Hat Ceph Storage 3 | grafana | Not affected | n/a |
| Red Hat Ceph Storage 4 | rhceph/rhceph-4-dashboard-rhel8 | Not affected | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox:flatpak/firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird:flatpak/thunderbird | Not affected | n/a |
| Red Hat Fuse 7 | angular | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | angular | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_2-eap6 | Out of support scope | n/a |
| Red Hat OpenStack Platform 16.1 | qpid-dispatch | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | qpid-dispatch | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
| Red Hat Satellite 6 | qpid-dispatch | Will not fix | n/a |
| Red Hat Single Sign-On 7 | keycloak-theme | Will not fix | n/a |
| Red Hat Storage 3 | grafana | Not affected | n/a |
angular
npm
Introduced 1.7.0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | angular | 1.7.0 | not fixed |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
2 other sources (GHSA, CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:F
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (32 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.93% (0.04927) | 91.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.37% (0.04368) | 89.98th | v5 (v2026.06.15) |
| Mar 4, 2026 | 1.92% (0.01924) | 83.10th | v4 (v2025.03.14) |
| Mar 1, 2026 | 0.78% (0.00779) | 73.46th | v4 (v2025.03.14) |
| Feb 4, 2026 | 1.92% (0.01924) | 82.98th | v4 (v2025.03.14) |
| Feb 1, 2026 | 0.78% (0.00779) | 73.32th | v4 (v2025.03.14) |
| Jan 4, 2026 | 1.92% (0.01924) | 82.91th | v4 (v2025.03.14) |
| Jan 1, 2026 | 0.78% (0.00779) | 73.26th | v4 (v2025.03.14) |
| Dec 4, 2025 | 1.92% (0.01924) | 82.80th | v4 (v2025.03.14) |
| Dec 1, 2025 | 0.78% (0.00779) | 73.01th | v4 (v2025.03.14) |
| Nov 21, 2025 | 1.92% (0.01924) | 82.81th | v4 (v2025.03.14) |
| Nov 18, 2025 | 7.08% (0.07078) | 90.61th | v4 (v2025.03.14) |
| Nov 4, 2025 | 1.61% (0.01609) | 81.13th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.41% (0.00407) | 58.22th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.74% (0.01741) | 71.18th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.41% (0.00407) | 59.03th | v4 (v2025.03.14) |
| Dec 12, 2024 | 1.69% (0.01694) | 88.23th | v3 (v2023.03.01) |
| Dec 21, 2023 | 1.13% (0.01132) | 83.05th | v3 (v2023.03.01) |
| Dec 7, 2023 | 0.95% (0.00946) | 81.33th | v3 (v2023.03.01) |
| Nov 22, 2023 | 0.77% (0.00773) | 79.24th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.69% (0.00686) | 77.75th | v3 (v2023.03.01) |
| Oct 12, 2023 | 0.47% (0.00475) | 72.93th | v3 (v2023.03.01) |
| Aug 6, 2023 | 0.40% (0.00399) | 70.14th | v3 (v2023.03.01) |
| Jun 3, 2023 | 0.34% (0.00340) | 67.22th | v3 (v2023.03.01) |
| May 8, 2023 | 0.28% (0.00283) | 63.76th | v3 (v2023.03.01) |
| Apr 1, 2023 | 0.22% (0.00218) | 58.16th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00180) | 53.38th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.18% (0.01183) | 61.76th | v2 (v2022.01.01) |
| Oct 29, 2022 | 1.18% (0.01183) | 60.86th | v2 (v2022.01.01) |
| Jun 30, 2022 | 1.11% (0.01108) | 52.58th | v2 (v2022.01.01) |
| May 12, 2022 | 1.02% (0.01018) | 37.33th | v2 (v2022.01.01) |
| May 2, 2022 | 0.95% (0.00950) | 28.96th | v2 (v2022.01.01) |
References (16)
- https://access.redhat.com/security/cve/CVE-2022-25844 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2080945 Issue Tracking
- https://github.com/advisories/GHSA-m2h2-264f-f486 Advisory
- https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2WUSPYOTOMAZPDEFPWPSCSPMNODRDKK3 vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LNAKCNTVBIHWAUT3FKWV5N67PQXSZOO vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WUSPYOTOMAZPDEFPWPSCSPMNODRDKK3
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LNAKCNTVBIHWAUT3FKWV5N67PQXSZOO
- https://nvd.nist.gov/vuln/detail/CVE-2022-25844
- https://security.netapp.com/advisory/ntap-20220629-0009 Third Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2772736 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2772738 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2772737 ExploitThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-ANGULAR-2772735 ExploitThird Party Advisory
- https://stackblitz.com/edit/angularjs-material-blank-zvtdvb ExploitThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-25844
Change history (0)
No recorded changes yet.