CVE-2024-21490
published 2024-02-10CVE-2024-21490: This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.89%
77.2th percentile
This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | 1.3.0 – 1.8.3 | — |
| angularjs | angular.js | >= 0 < 1.8.3-1+deb12u1~deb11u1 | 1.8.3-1+deb12u1~deb11u1 |
| angularjs | angular.js | >= 0 < 1.8.3-1+deb12u1 | 1.8.3-1+deb12u1 |
| angularjs | angular.js | >= 0 < 1.8.3-2 | 1.8.3-2 |
| angularjs | angular.js | >= 0 < 1.8.3-2 | 1.8.3-2 |
| angularjs | angular.js | >= 1.3.0 | — |
| debian | angular.js | < angular.js 1.8.3-1+deb12u1 (bookworm) | angular.js 1.8.3-1+deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
angular.js vulnerabilities
osv·2026-01-14·CVSS 6.1
CVE-2019-14863 [MEDIUM] angular.js vulnerabilities
angular.js vulnerabilities
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of s
GHSA
angular vulnerable to super-linear runtime due to backtracking
ghsa·2024-02-10
CVE-2024-21490 [HIGH] CWE-1333 angular vulnerable to super-linear runtime due to backtracking
angular vulnerable to super-linear runtime due to backtracking
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.
**Note:**
This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
OSV
angular vulnerable to super-linear runtime due to backtracking
osv·2024-02-10
CVE-2024-21490 [HIGH] angular vulnerable to super-linear runtime due to backtracking
angular vulnerable to super-linear runtime due to backtracking
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.
**Note:**
This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
OSV
CVE-2024-21490: This affects versions of the package angular from 1
osv·2024-02-10·CVSS 7.5
CVE-2024-21490 [HIGH] CVE-2024-21490: This affects versions of the package angular from 1
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Ubuntu
AngularJS vulnerabilities
vendor_ubuntu·2026-01-14·CVSS 6.1
CVE-2024-8372 [MEDIUM] AngularJS vulnerabilities
Title: AngularJS vulnerabilities
Summary: Several security issues were fixed in AngularJS.
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
Red Hat
angular: Inefficient Regular Expression Complexity
vendor_redhat·2024-02-10·CVSS 7.5
CVE-2024-21490 [HIGH] CWE-1333 angular: Inefficient Regular Expression Complexity
angular: Inefficient Regular Expression Complexity
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.
**Note:**
This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
An Inefficient Regular Expression Complexity vulnerability was found in NodeJS Angular. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking, leading to denial of service.
Statement: The vulnerabil
Debian
CVE-2024-21490: angular.js - This affects versions of the package angular from 1.3.0. A regular expression us...
vendor_debian·2024·CVSS 7.5
CVE-2024-21490 [HIGH] CVE-2024-21490: angular.js - This affects versions of the package angular from 1.3.0. A regular expression us...
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Scope: local
bookworm: resolved (fixed in 1.8.3-1+deb12u1)
bullseye: resolved (fixed in 1.8.3-1+deb12u1~deb11u1)
forky: resolved (fixed in 1.8.3-2)
sid: resolved (fixed in 1.8.3-2)
trixie: resolved (fixed in 1.8.3-2)
No detection rules found.
No public exploits indexed.
https://security.snyk.io/vuln/SNYK-DOTNET-ANGULARJS-10771616https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-6241746https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6241747https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113https://stackblitz.com/edit/angularjs-vulnerability-ng-srcset-redoshttps://lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlhttps://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-6241746https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6241747https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113https://stackblitz.com/edit/angularjs-vulnerability-ng-srcset-redoshttps://support.herodevs.com/hc/en-us/articles/25715686953485-CVE-2024-21490-AngularJS-Regular-Expression-Denial-of-Service-ReDoS
2024-02-10
Published