CVE-2023-26116
published 2023-03-30CVE-2023-26116: Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.70%
74.6th percentile
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | 0 – 1.8.3 | — |
| angularjs | angularjs | 1.2.21 – 1.8.3 | — |
| debian | angular.js | < angular.js 1.8.3-1+deb12u1 (bookworm) | angular.js 1.8.3-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
angular.js vulnerabilities
osv·2026-01-14·CVSS 6.1
CVE-2019-14863 [MEDIUM] angular.js vulnerabilities
angular.js vulnerabilities
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of s
OSV
angular vulnerable to regular expression denial of service via the angular.copy() utility
osv·2023-03-30
CVE-2023-26116 [MEDIUM] angular vulnerable to regular expression denial of service via the angular.copy() utility
angular vulnerable to regular expression denial of service via the angular.copy() utility
All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
GHSA
angular vulnerable to regular expression denial of service via the angular.copy() utility
ghsa·2023-03-30
CVE-2023-26116 [MEDIUM] CWE-1333 angular vulnerable to regular expression denial of service via the angular.copy() utility
angular vulnerable to regular expression denial of service via the angular.copy() utility
All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
OSV
CVE-2023-26116: Versions of the package angular from 1
osv·2023-03-30·CVSS 5.3
CVE-2023-26116 [MEDIUM] CVE-2023-26116: Versions of the package angular from 1
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Ubuntu
AngularJS vulnerabilities
vendor_ubuntu·2026-01-14·CVSS 6.1
CVE-2024-8372 [MEDIUM] AngularJS vulnerabilities
Title: AngularJS vulnerabilities
Summary: Several security issues were fixed in AngularJS.
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
Red Hat
angularjs: Regular Expression Denial of Service via angular.copy()
vendor_redhat·2023-03-30·CVSS 5.3
CVE-2023-26116 [MEDIUM] CWE-1333 angularjs: Regular Expression Denial of Service via angular.copy()
angularjs: Regular Expression Denial of Service via angular.copy()
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
A flaw was found in AngularJS, where it is vulnerable to a denial of service caused by a regular expression denial of service (ReDoS) flaw in the angular.copy() utility function. By providing specially-crafted regex input, a remote attacker can cause a denial of service.
Package: servicemesh-grafana (OpenShift Service Mesh 2.1) - Will not fix
Package: angular (Red Hat Ansible Tower 3) - Not affected
P
Debian
CVE-2023-26116: angular.js - Versions of the package angular from 1.2.21 are vulnerable to Regular Expression...
vendor_debian·2023·CVSS 5.3
CVE-2023-26116 [MEDIUM] CVE-2023-26116: angular.js - Versions of the package angular from 1.2.21 are vulnerable to Regular Expression...
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Scope: local
bookworm: resolved (fixed in 1.8.3-1+deb12u1)
bullseye: resolved (fixed in 1.8.3-1+deb12u1~deb11u1)
forky: resolved (fixed in 1.8.3-2)
sid: resolved (fixed in 1.8.3-2)
trixie: resolved (fixed in 1.8.3-2)
No detection rules found.
No public exploits indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406320https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406322https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406321https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373044https://stackblitz.com/edit/angularjs-vulnerability-angular-copy-redoshttps://lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406320https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406322https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406321https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373044https://stackblitz.com/edit/angularjs-vulnerability-angular-copy-redos
2023-03-30
Published