cbcvebase.
CVE-2023-26118
published 2023-03-30

CVE-2023-26118: Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure…

PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.70%
74.6th percentile
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

Affected

4 ranges
VendorProductVersion rangeFixed in
angularangular0 – 1.8.3
angularjsangularjs1.4.9 – 1.8.3
debianangular.js< angular.js 1.8.3-1+deb12u1 (bookworm)angular.js 1.8.3-1+deb12u1 (bookworm)
fedoraprojectfedora

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.