Regular Expression Denial of Service Vulnerability in Angular from Vendor
CVE-2023-26118
5.3MEDIUM
What is CVE-2023-26118?
AngularJS versions from 1.4.9 are susceptible to a Regular Expression Denial of Service (ReDoS) vulnerability stemming from the use of an insecure regular expression in the input[type='url'] element. An attacker can exploit this vulnerability by submitting a specially crafted large input that results in excessive backtracking, causing the application to hang or crash.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
angular 1.4.9
org.webjars.bower:angular 1.4.9
org.webjars.bowergithub.angular:angular 0
