GHSA-4w4v-5hc9-xrr2
angular vulnerable to super-linear runtime due to backtracking
Details
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.
**Note:**
This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Are you affected?
Enter the version of the package you're using.
Affected packages
1.3.0No fixed version published yet for angular (npm). Pin to a known-safe version or switch to an alternative.
1.3.0No fixed version published yet for org.webjars.npm:angular (maven). Pin to a known-safe version or switch to an alternative.
1.3.0No fixed version published yet for org.webjars.bower:angular (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-21490[ADVISORY]
- https://github.com/angular/angular.js[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html[WEB]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-6241746[WEB]
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6241747[WEB]
- https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113[WEB]
- https://stackblitz.com/edit/angularjs-vulnerability-ng-srcset-redos[WEB]
- https://support.herodevs.com/hc/en-us/articles/25715686953485-CVE-2024-21490-AngularJS-Regular-Expression-Denial-of-Service-ReDoS[WEB]