VDB
Sign up
HIGH7.5

GHSA-4w4v-5hc9-xrr2

angular vulnerable to super-linear runtime due to backtracking

Details

This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.

**Note:**

This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/angular
Introduced in: 1.3.0

No fixed version published yet for angular (npm). Pin to a known-safe version or switch to an alternative.

Maven/org.webjars.npm:angular
Introduced in: 1.3.0

No fixed version published yet for org.webjars.npm:angular (maven). Pin to a known-safe version or switch to an alternative.

Maven/org.webjars.bower:angular
Introduced in: 1.3.0

No fixed version published yet for org.webjars.bower:angular (maven). Pin to a known-safe version or switch to an alternative.

References