Medium severity5.3OSV Advisory· Published Mar 30, 2023· Updated Jun 17, 2026
CVE-2023-26117
CVE-2023-26117
Description
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
angularnpm | <= 1.8.3 | — |
Affected products
8- Range: v1.0.0, v1.0.1, v1.1.0, …
- ghsa-coords5 versionspkg:npm/angularpkg:apk/chainguard/solr-oci-compatpkg:apk/chainguard/solrpkg:apk/wolfi/solrpkg:apk/wolfi/solr-oci-compat
<= 1.8.3+ 4 more
- (no CPE)range: <= 1.8.3
- (no CPE)range: < 9.9.0-r3
- (no CPE)range: < 9.10.0-r0
- (no CPE)range: < 9.10.0-r0
- (no CPE)range: < 9.9.0-r3
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
12- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-5406323nvdExploitThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBANGULAR-5406325nvdExploitThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-5406324nvdExploitThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-ANGULAR-3373045nvdExploitThird Party AdvisoryWEB
- stackblitz.com/edit/angularjs-vulnerability-resource-trailing-slashes-redosnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-2qqx-w9hr-q5gxghsaADVISORY
- lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJ/nvdMailing ListThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2023-26117ghsaADVISORY
- lists.debian.org/debian-lts-announce/2025/07/msg00005.htmlnvdWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/OQWJLE5WE33WNMA54XSJIDXBRK2KL3XJghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55KghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/UDKFLKJ6VZKL52AFVW2OVZRMJWHMW55K/nvd
News mentions
0No linked articles in our index yet.