Back

HIGH

angular: Inefficient Regular Expression Complexity

Published Feb 10, 2024

Description

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).

Affected products

Remediation

Red Hat statement

The vulnerability in the Angular package, has been categorized as having a moderate severity rather than being labeled as important due to several factors. While the regular expression used for splitting the value of the ng-srcset directive is susceptible to super-linear runtime caused by backtracking, the practical exploitation of this vulnerability requires a large, carefully-crafted input. This input, which triggers catastrophic backtracking and potential denial of service, would not be easily achievable in typical use cases. Additionally, the affected package, Angular 1.3.0, is already designated as End of Life (EOL) and is not receiving updates, limiting its relevance to current development practices. Red Hat Enterprise Linux is not affected as its not shipping the vulnerable code.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Feb 10, 2024
Updated Jul 6, 2026
Reserved Dec 22, 2023
CISA Vulnrichment
Updated Feb 12, 2024
NVD
Status Modified
Modified Jun 29, 2026
Red Hat
Severity Moderate
Public date Feb 10, 2024
GHSA-4W4V-5HC9-XRR2