CVE-2023-26118
published 2023-03-30CVE-2023-26118: Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure…
PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.70%
74.6th percentile
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | 0 – 1.8.3 | — |
| angularjs | angularjs | 1.4.9 – 1.8.3 | — |
| debian | angular.js | < angular.js 1.8.3-1+deb12u1 (bookworm) | angular.js 1.8.3-1+deb12u1 (bookworm) |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
angular.js vulnerabilities
osv·2026-01-14·CVSS 6.1
CVE-2019-14863 [MEDIUM] angular.js vulnerabilities
angular.js vulnerabilities
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of s
OSV
CVE-2023-26118: Versions of the package angular from 1
osv·2023-03-30·CVSS 5.3
CVE-2023-26118 [MEDIUM] CVE-2023-26118: Versions of the package angular from 1
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
OSV
angular vulnerable to regular expression denial of service via the <input type="url"> element
osv·2023-03-30
CVE-2023-26118 [MEDIUM] angular vulnerable to regular expression denial of service via the <input type="url"> element
angular vulnerable to regular expression denial of service via the element
All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
GHSA
angular vulnerable to regular expression denial of service via the <input type="url"> element
ghsa·2023-03-30
CVE-2023-26118 [MEDIUM] CWE-1333 angular vulnerable to regular expression denial of service via the <input type="url"> element
angular vulnerable to regular expression denial of service via the element
All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Ubuntu
AngularJS vulnerabilities
vendor_ubuntu·2026-01-14·CVSS 6.1
CVE-2024-8372 [MEDIUM] AngularJS vulnerabilities
Title: AngularJS vulnerabilities
Summary: Several security issues were fixed in AngularJS.
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
Red Hat
angularjs: Regular Expression Denial of Service via the <input type="url"> element
vendor_redhat·2023-03-30·CVSS 5.3
CVE-2023-26118 [MEDIUM] CWE-1333 angularjs: Regular Expression Denial of Service via the <input type="url"> element
angularjs: Regular Expression Denial of Service via the element
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
A flaw was found in AngularJS, where it is vulnerable to a denial of service caused by a regular expression denial of service (ReDoS) flaw in the input[url] functionality. By providing specially-crafted regex input, a remote attacker can cause a denial of service.
Statement: In Quay 3.10 and above, no version of affected momentjs is present.
Package: servicemesh-grafana (OpenShift Service Mesh 2.1)
Debian
CVE-2023-26118: angular.js - Versions of the package angular from 1.4.9 are vulnerable to Regular Expression ...
vendor_debian·2023·CVSS 5.3
CVE-2023-26118 [MEDIUM] CVE-2023-26118: angular.js - Versions of the package angular from 1.4.9 are vulnerable to Regular Expression ...
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
Scope: local
bookworm: resolved (fixed in 1.8.3-1+deb12u1)
bullseye: resolved (fixed in 1.8.3-1+deb12u1~deb11u1)
forky: resolved (fixed in 1.8.3-2)
sid: resolved (fixed in 1.8.3-2)
trixie: resolved (fixed in 1.8.3-2)
No detection rules found.
No public exploits indexed.
https://lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406326https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406328https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406327https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373046https://stackblitz.com/edit/angularjs-vulnerability-inpur-url-validation-redoshttps://lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406326https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406328https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406327https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373046https://stackblitz.com/edit/angularjs-vulnerability-inpur-url-validation-redos
2023-03-30
Published