GHSA-qwqh-hm9m-p5hr

Suggest an improvement
Source
https://github.com/advisories/GHSA-qwqh-hm9m-p5hr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-qwqh-hm9m-p5hr/GHSA-qwqh-hm9m-p5hr.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-qwqh-hm9m-p5hr
Aliases
Downstream
CGA (2)
MINI (1)
Published
2023-03-30T06:30:25Z
Modified
2026-07-17T21:11:09Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
angular vulnerable to regular expression denial of service via the <input type="url"> element
Details

All versions of the package angular are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.

Database specific
{
    "cwe_ids": [
        "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2023-04-03T13:07:41Z",
    "nvd_published_at": "2023-03-30T05:15:00Z",
    "severity": "MODERATE"
}
References

Affected packages

npm / angular

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.8.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-qwqh-hm9m-p5hr/GHSA-qwqh-hm9m-p5hr.json"