angular: Inefficient Regular Expression Complexity
Published Feb 10, 2024
7.5
HIGHCVSS 3.1
EPSS 1.89%
Description
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Affected products
- Vendor n/a Product Angular Defaultn/a
- Version 1.3.0StatusaffectedConstraints<*
- Version
- Vendor n/a Product Angularjs Defaultn/a
- Version 1.3.0StatusaffectedConstraints<*
- Version
- Vendor n/a Product Org.webjars.bower:angular Defaultn/a
- Version 1.3.0StatusaffectedConstraints<*
- Version
- Vendor n/a Product Org.webjars.npm:angular Defaultn/a
- Version 1.3.0StatusaffectedConstraints<*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Angular | n/a |
| ||||||
| n/a | Angularjs | n/a |
| ||||||
| n/a | Org.webjars.bower:angular | n/a |
| ||||||
| n/a | Org.webjars.npm:angular | n/a |
|
- ≥ 1.3.0
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
Red Hat Enterprise Linux 6
firefox
Not affected
Red Hat Enterprise Linux 6
thunderbird
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 7
thunderbird
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
firefox:flatpak/firefox
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 8
thunderbird:flatpak/thunderbird
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
firefox:flatpak/firefox
Not affected
Red Hat Enterprise Linux 9
gjs
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Enterprise Linux 9
thunderbird:flatpak/thunderbird
Not affected
Red Hat Fuse 7
angular
Will not fix
Red Hat JBoss Data Grid 7
angular
Not affected
Red Hat JBoss Enterprise Application Platform 7
angular
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
angular
Not affected
Red Hat OpenStack Platform 16.1
qpid-dispatch
Not affected
Red Hat OpenStack Platform 16.2
qpid-dispatch
Not affected
Red Hat Quay 3
quay/quay-rhel8
Not affected
Red Hat Satellite 6
nodejs-angular
Affected
Red Hat Single Sign-On 7
rh-sso7-keycloak
Will not fix
Red Hat Storage 3
grafana
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 6 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox:flatpak/firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird:flatpak/thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox:flatpak/firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird:flatpak/thunderbird | Not affected | n/a |
| Red Hat Fuse 7 | angular | Will not fix | n/a |
| Red Hat JBoss Data Grid 7 | angular | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | angular | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | angular | Not affected | n/a |
| Red Hat OpenStack Platform 16.1 | qpid-dispatch | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | qpid-dispatch | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
| Red Hat Satellite 6 | nodejs-angular | Affected | n/a |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Will not fix | n/a |
| Red Hat Storage 3 | grafana | Out of support scope | n/a |
angular
npm
Introduced 1.3.0 Fixed not fixedorg.webjars.npm:angular
Maven
Introduced 1.3.0 Fixed not fixedorg.webjars.bower:angular
Maven
Introduced 1.3.0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | angular | 1.3.0 | not fixed |
| Maven | org.webjars.npm:angular | 1.3.0 | not fixed |
| Maven | org.webjars.bower:angular | 1.3.0 | not fixed |
Remediation
Red Hat statement
The vulnerability in the Angular package, has been categorized as having a moderate severity rather than being labeled as important due to several factors. While the regular expression used for splitting the value of the ng-srcset directive is susceptible to super-linear runtime caused by backtracking, the practical exploitation of this vulnerability requires a large, carefully-crafted input. This input, which triggers catastrophic backtracking and potential denial of service, would not be easily achievable in typical use cases. Additionally, the affected package, Angular 1.3.0, is already designated as End of Life (EOL) and is not receiving updates, limiting its relevance to current development practices. Red Hat Enterprise Linux is not affected as its not shipping the vulnerable code.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 12, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.89% (0.01891) | 78.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.81% (0.01810) | 75.72th | v5 (v2026.06.15) |
| Feb 4, 2026 | 1.71% (0.01714) | 81.96th | v4 (v2025.03.14) |
| Feb 1, 2026 | 0.71% (0.00711) | 71.91th | v4 (v2025.03.14) |
| Jan 18, 2026 | 1.71% (0.01714) | 81.91th | v4 (v2025.03.14) |
| Jan 1, 2026 | 0.69% (0.00691) | 71.39th | v4 (v2025.03.14) |
| Dec 4, 2025 | 1.71% (0.01714) | 81.78th | v4 (v2025.03.14) |
| Dec 1, 2025 | 0.71% (0.00711) | 71.60th | v4 (v2025.03.14) |
| Nov 21, 2025 | 1.71% (0.01714) | 81.78th | v4 (v2025.03.14) |
| Nov 18, 2025 | 8.88% (0.08885) | 91.71th | v4 (v2025.03.14) |
| Nov 4, 2025 | 1.67% (0.01669) | 81.49th | v4 (v2025.03.14) |
| May 1, 2025 | 0.38% (0.00375) | 58.25th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.59% (0.01590) | 79.96th | v4 (v2025.03.14) |
| Mar 29, 2025 | 5.92% (0.05921) | 83.94th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.59% (0.01590) | 80.38th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00052) | 22.07th | v3 (v2023.03.01) |
| May 18, 2024 | 0.05% (0.00052) | 19.65th | v3 (v2023.03.01) |
| Mar 7, 2024 | 0.05% (0.00052) | 17.64th | v3 (v2023.03.01) |
| Feb 17, 2024 | 0.05% (0.00046) | 13.64th | v3 (v2023.03.01) |
| Feb 10, 2024 | 0.04% (0.00043) | 6.67th | v3 (v2023.03.01) |
References (12)
- https://access.redhat.com/security/cve/CVE-2024-21490 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2263754 Issue Tracking
- https://github.com/advisories/GHSA-4w4v-5hc9-xrr2 Advisory
- https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html
- https://nvd.nist.gov/vuln/detail/CVE-2024-21490
- https://security.snyk.io/vuln/SNYK-DOTNET-ANGULARJS-10771616
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-6241746 Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6241747 Third Party Advisory
- https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113 Third Party Advisory
- https://stackblitz.com/edit/angularjs-vulnerability-ng-srcset-redos ExploitThird Party Advisory
- https://support.herodevs.com/hc/en-us/articles/25715686953485-CVE-2024-21490-AngularJS-Regular-Expression-Denial-of-Service-ReDoS Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2024-21490
Change history (0)
No recorded changes yet.