VDB
Sign up
MEDIUM5.3

GHSA-m2h2-264f-f486

angular vulnerable to regular expression denial of service (ReDoS)

Details

AngularJS lets users write client-side web applications. The package angular after 1.7.0 is vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value.

**Note:** 1. This package has been deprecated and is no longer maintained. 2. The vulnerable versions are 1.7.0 and higher.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/angular
Introduced in: 1.7.0

No fixed version published yet for angular (npm). Pin to a known-safe version or switch to an alternative.

References