GHSA-m2h2-264f-f486
Dashboard / Vulnerabilities / GHSA-m2h2-264f-f486
Summary: angular vulnerable to regular expression denial of service (ReDoS)
Details: AngularJS lets users write client-side web applications. The package angular after 1.7.0 is vulnerable to Regular Expression Denial of Service (ReDoS) by providing a custom locale rule that makes it possible to assign the parameter in posPre: ' '.repeat() of NUMBER_FORMATS.PATTERNS[1].posPre with a very high value. **Note:** 1. This package has been deprecated and is no longer maintained. 2. The vulnerable versions are 1.7.0 and higher.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-25844, https://github.com/angular/angular.js, https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2WUSPYOTOMAZPDEFPWPSCSPMNODRDKK3, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7LNAKCNTVBIHWAUT3FKWV5N67PQXSZOO, https://lists.fedoraproject.org/archives/list/[email protected]/message/2WUSPYOTOMAZPDEFPWPSCSPMNODRDKK3, https://lists.fedoraproject.org/archives/list/[email protected]/message/7LNAKCNTVBIHWAUT3FKWV5N67PQXSZOO, https://security.netapp.com/advisory/ntap-20220629-0009, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2772736, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-2772738, https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2772737, https://snyk.io/vuln/SNYK-JS-ANGULAR-2772735, https://stackblitz.com/edit/angularjs-material-blank-zvtdvb
Affected packages
Package
Name: angular
Purl: pkg:npm/angular
Affected ranges
Type: SEMVER
Events:
