Description
This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service.
Note:
This package is EOL and will not receive any updates to address this issue. Users should migrate to @angular/core.
Remediation
References
Related Vulnerabilities
WordPress Plugin Ultimate TinyMCE Multiple Unspecified Vulnerabilities (5.0)
Angular Uncontrolled Resource Consumption Vulnerability (CVE-2026-54268)
WordPress Plugin Brizy-Page Builder Arbitrary File Upload (2.4.44)
Oracle Database Server Uncontrolled Resource Consumption Vulnerability (CVE-2024-21126)
Masa CMS Incorrect Authorization Vulnerability (CVE-2024-32643)