CVE-2023-26117
published 2023-03-30CVE-2023-26117: Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.70%
74.6th percentile
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | 0 – 1.8.3 | — |
| angularjs | angularjs | 1.0.0 – 1.8.3 | — |
| debian | angular.js | < angular.js 1.8.3-1+deb12u1 (bookworm) | angular.js 1.8.3-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv6.1MEDIUM
vendor_oracle7.5HIGH
vendor_ubuntu6.1MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
angular.js vulnerabilities
osv·2026-01-14·CVSS 6.1
CVE-2019-14863 [MEDIUM] angular.js vulnerabilities
angular.js vulnerabilities
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of s
GHSA
angular vulnerable to regular expression denial of service via the $resource service
ghsa·2023-03-30
CVE-2023-26117 [MEDIUM] CWE-1333 angular vulnerable to regular expression denial of service via the $resource service
angular vulnerable to regular expression denial of service via the $resource service
All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
OSV
angular vulnerable to regular expression denial of service via the $resource service
osv·2023-03-30
CVE-2023-26117 [MEDIUM] angular vulnerable to regular expression denial of service via the $resource service
angular vulnerable to regular expression denial of service via the $resource service
All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
OSV
CVE-2023-26117: Versions of the package angular from 1
osv·2023-03-30·CVSS 5.3
CVE-2023-26117 [MEDIUM] CVE-2023-26117: Versions of the package angular from 1
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Ubuntu
AngularJS vulnerabilities
vendor_ubuntu·2026-01-14·CVSS 6.1
CVE-2024-8372 [MEDIUM] AngularJS vulnerabilities
Title: AngularJS vulnerabilities
Summary: Several security issues were fixed in AngularJS.
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache ActiveMQ) — CVE-2021-26117
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2021-26117 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: General (Apache ActiveMQ) — CVE-2021-26117
Oracle Oracle Fusion Middleware Risk Matrix: General (Apache ActiveMQ) vulnerability
CVE: CVE-2021-26117
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Red Hat
angularjs: Regular expression denial of service via the $resource service
vendor_redhat·2023-03-30·CVSS 5.3
CVE-2023-26117 [MEDIUM] CWE-1333 angularjs: Regular expression denial of service via the $resource service
angularjs: Regular expression denial of service via the $resource service
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
A flaw was found in AngularJS, where it is vulnerable to a denial of service caused by a regular expression denial of service (ReDoS) issue in the $resource service. By providing specially-crafted regex input, a remote attacker could cause a denial of service.
Statement: In Quay 3.10 and above, no version of affected momentjs is present.
Package: servicemesh-grafana (OpenShift Service Mesh 2.1) - Will not fix
Debian
CVE-2023-26117: angular.js - Versions of the package angular from 1.0.0 are vulnerable to Regular Expression ...
vendor_debian·2023·CVSS 5.3
CVE-2023-26117 [MEDIUM] CVE-2023-26117: angular.js - Versions of the package angular from 1.0.0 are vulnerable to Regular Expression ...
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Scope: local
bookworm: resolved (fixed in 1.8.3-1+deb12u1)
bullseye: resolved (fixed in 1.8.3-1+deb12u1~deb11u1)
forky: resolved (fixed in 1.8.3-2)
sid: resolved (fixed in 1.8.3-2)
trixie: resolved (fixed in 1.8.3-2)
No detection rules found.
No public exploits indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406323https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406325https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406324https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373045https://stackblitz.com/edit/angularjs-vulnerability-resource-trailing-slashes-redoshttps://lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406323https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406325https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406324https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373045https://stackblitz.com/edit/angularjs-vulnerability-resource-trailing-slashes-redos
2023-03-30
Published