MEDIUM5.3
GHSA-m2h2-264f-f486
angular vulnerable to regular expression denial of service (ReDoS)
Details
AngularJS lets users write client-side web applications. The package angular after 1.7.0 is vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value.
**Note:** 1. This package has been deprecated and is no longer maintained. 2. The vulnerable versions are 1.7.0 and higher.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/angular
Introduced in:
1.7.0No fixed version published yet for angular (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25844[ADVISORY]
- https://github.com/angular/angular.js[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2WUSPYOTOMAZPDEFPWPSCSPMNODRDKK3[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LNAKCNTVBIHWAUT3FKWV5N67PQXSZOO[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2WUSPYOTOMAZPDEFPWPSCSPMNODRDKK3[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7LNAKCNTVBIHWAUT3FKWV5N67PQXSZOO[WEB]
- https://security.netapp.com/advisory/ntap-20220629-0009[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2772736[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2772738[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2772737[WEB]
- https://snyk.io/vuln/SNYK-JS-ANGULAR-2772735[WEB]
- https://stackblitz.com/edit/angularjs-material-blank-zvtdvb[WEB]