{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2023-26117","assignerOrgId":"bae035ff-b466-4ff4-94d0-fc9efd9e1730","state":"PUBLISHED","assignerShortName":"snyk","dateReserved":"2023-02-20T10:28:48.923Z","datePublished":"2023-03-30T05:00:01.348Z","dateUpdated":"2025-11-03T19:28:07.269Z"},"containers":{"cna":{"affected":[{"product":"angular","vendor":"n/a","versions":[{"lessThan":"*","status":"affected","version":"1.0.0","versionType":"semver"}]},{"product":"org.webjars.bower:angular","vendor":"n/a","versions":[{"lessThan":"*","status":"affected","version":"1.0.0","versionType":"semver"}]},{"product":"org.webjars.npm:angular","vendor":"n/a","versions":[{"lessThan":"*","status":"affected","version":"1.0.0","versionType":"semver"}]},{"product":"org.webjars.bowergithub.angular:angular","vendor":"n/a","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"semver"}]}],"metrics":[{"cvssV3_1":{"attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P","version":"3.1"}}],"providerMetadata":{"orgId":"bae035ff-b466-4ff4-94d0-fc9efd9e1730","shortName":"snyk","dateUpdated":"2023-11-03T20:07:35.924Z"},"descriptions":[{"lang":"en","value":"Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking."}],"references":[{"url":"https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373045"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406323"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406324"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406325"},{"url":"https://stackblitz.com/edit/angularjs-vulnerability-resource-trailing-slashes-redos"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/"}],"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-1333","description":"Regular Expression Denial of Service (ReDoS)"}]}],"credits":[{"lang":"en","value":"Michael Prentice"},{"lang":"en","value":"George Kalpakas"}]},"adp":[{"title":"CVE Program Container","references":[{"url":"https://security.snyk.io/vuln/SNYK-JS-ANGULAR-3373045","tags":["x_transferred"]},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406323","tags":["x_transferred"]},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406324","tags":["x_transferred"]},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406325","tags":["x_transferred"]},{"url":"https://stackblitz.com/edit/angularjs-vulnerability-resource-trailing-slashes-redos","tags":["x_transferred"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/","tags":["x_transferred"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/","tags":["x_transferred"]},{"url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T19:28:07.269Z"}},{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-1333","lang":"en","description":"CWE-1333 Inefficient Regular Expression Complexity"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-02-14T15:38:00.220683Z","id":"CVE-2023-26117","options":[{"Exploitation":"poc"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-02-14T15:38:14.201Z"}}]}}