CVE-2025-0716
published 2025-04-29CVE-2025-0716: Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source…
PriorityP422medium4.8CVSS 3.1
AVNACHPRNUINSUCNILAL
EPSS
0.38%
29.7th percentile
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.
This issue affects all versions of AngularJS.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | 0 – 1.8.3 | — |
| debian | angular.js | < angular.js 1.8.3-1+deb12u1 (bookworm) | angular.js 1.8.3-1+deb12u1 (bookworm) |
| angularjs | — | — |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
angular.js vulnerabilities
osv·2026-01-14·CVSS 6.1
CVE-2019-14863 [MEDIUM] angular.js vulnerabilities
angular.js vulnerabilities
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of s
OSV
AngularJS improperly sanitizes SVG elements
osv·2025-04-29
CVE-2025-0716 [LOW] AngularJS improperly sanitizes SVG elements
AngularJS improperly sanitizes SVG elements
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.
This issue affects all versions of AngularJS.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
GHSA
AngularJS improperly sanitizes SVG elements
ghsa·2025-04-29
CVE-2025-0716 [LOW] CWE-791 AngularJS improperly sanitizes SVG elements
AngularJS improperly sanitizes SVG elements
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.
This issue affects all versions of AngularJS.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
OSV
CVE-2025-0716: Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image s
osv·2025-04-29·CVSS 4.8
CVE-2025-0716 [MEDIUM] CVE-2025-0716: Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image s
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Ubuntu
AngularJS vulnerabilities
vendor_ubuntu·2026-01-14·CVSS 6.1
CVE-2024-8372 [MEDIUM] AngularJS vulnerabilities
Title: AngularJS vulnerabilities
Summary: Several security issues were fixed in AngularJS.
It was discovered that AngularJS did not properly sanitize certain
`xlink:href` attributes. A remote attacker could possibly use this issue
to perform cross site scripting. This issue only affected Ubuntu 16.04
LTS. (CVE-2019-14863)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
to consume resources, leading to a regular expression denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS and Ubuntu 25.04. (CVE-2022-25844)
It was discovered that AngularJS incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause AngularJS
Red Hat
angular: AngularJS improper sanitization in SVG '<image>' element
vendor_redhat·2025-04-29·CVSS 4.8
CVE-2025-0716 [MEDIUM] CWE-791 angular: AngularJS improper sanitization in SVG '<image>' element
angular: AngularJS improper sanitization in SVG '' element
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.
This issue affects all versions of AngularJS.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
A flaw was found in the angular package. Improper sanitization of the value of the 'href' and 'xlink:href' attributes in ''
Debian
CVE-2025-0716: angular.js - Improper sanitization of the value of the 'href' and 'xlink:href' attributes in ...
vendor_debian·2025·CVSS 4.8
CVE-2025-0716 [MEDIUM] CVE-2025-0716: angular.js - Improper sanitization of the value of the 'href' and 'xlink:href' attributes in ...
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images. This issue affects all versions of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
Scope: local
bookworm: resolved (fixed in 1.8.3-1+deb12u1)
bullseye: resolved (fixed in 1.8.3-1+deb12u1~deb11u1)
forky: resolved (fixed in 1.8.3-2)
sid: resolved (fixed in 1.8.3-2)
tri
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-0716 thunderbird: AngularJS improper sanitization in SVG '<image>' element [fedora-42]
bugzilla·2025-04-30·CVSS 4.8
CVE-2025-0716 [MEDIUM] CVE-2025-0716 thunderbird: AngularJS improper sanitization in SVG '<image>' element [fedora-42]
CVE-2025-0716 thunderbird: AngularJS improper sanitization in SVG '' element [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2362958
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Bugzilla
CVE-2025-0716 grafana: AngularJS improper sanitization in SVG '<image>' element [fedora-42]
bugzilla·2025-04-30·CVSS 4.8
CVE-2025-0716 [MEDIUM] CVE-2025-0716 grafana: AngularJS improper sanitization in SVG '<image>' element [fedora-42]
CVE-2025-0716 grafana: AngularJS improper sanitization in SVG '' element [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2362958
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Pac
Bugzilla
CVE-2025-0716 icecat: AngularJS improper sanitization in SVG '<image>' element [fedora-42]
bugzilla·2025-04-30·CVSS 4.8
CVE-2025-0716 [MEDIUM] CVE-2025-0716 icecat: AngularJS improper sanitization in SVG '<image>' element [fedora-42]
CVE-2025-0716 icecat: AngularJS improper sanitization in SVG '' element [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2362958
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Pack
Bugzilla
CVE-2025-0716 angular: AngularJS improper sanitization in SVG '<image>' element
bugzilla·2025-04-29·CVSS 4.8
CVE-2025-0716 [MEDIUM] CVE-2025-0716 angular: AngularJS improper sanitization in SVG '<image>' element
CVE-2025-0716 angular: AngularJS improper sanitization in SVG '' element
Improper sanitization of the value of the 'href' and 'xlink:href' attributes in '' SVG elements in AngularJS allows attackers to bypass common image source restrictions. This can lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing and also negatively affect the application's performance and behavior by using too large or slow-to-load images.
This issue affects all versions of AngularJS.
Note:
The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
https://codepen.io/herodevs/pen/qEWQmpd/a86a0d29310e12c7a3756768e6c7b915https://www.herodevs.com/vulnerability-directory/cve-2025-0716https://lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlhttps://codepen.io/herodevs/pen/qEWQmpd/a86a0d29310e12c7a3756768e6c7b915https://www.herodevs.com/vulnerability-directory/cve-2025-0716
2025-04-29
Published