CVE-2023-26118

Source
https://cve.org/CVERecord?id=CVE-2023-26118
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26118.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-26118
Aliases
Downstream
Related
Published
2023-03-30T05:00:02Z
Modified
2026-08-12T03:51:17Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P CVSS Calculator
Summary
[none]
Details

Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

Database specific
{
    "cna_assigner": "snyk",
    "cwe_ids": [
        "CWE-1333"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/26xxx/CVE-2023-26118.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "1.4.9"
                },
                {
                    "fixed": "*"
                },
                {
                    "introduced": "1.4.9"
                },
                {
                    "fixed": "*"
                },
                {
                    "introduced": "1.4.9"
                },
                {
                    "fixed": "*"
                },
                {
                    "fixed": "*"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/angular/angular.js

Affected ranges

Type
GIT
Repo
https://github.com/angular/angular.js
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:angularjs:angularjs:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "1.4.9"
        },
        {
            "last_affected": "1.8.3"
        }
    ],
    "source": "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-26118.json"