{"id":"GHSA-4w4v-5hc9-xrr2","summary":"angular vulnerable to super-linear runtime due to backtracking","details":"This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. \n\n\n**Note:**\n\nThis package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).","aliases":["CVE-2024-21490"],"modified":"2026-07-17T21:07:29.818084301Z","published":"2024-02-10T06:30:19Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-02-13T15:08:21Z","nvd_published_at":"2024-02-10T05:15:08Z","cwe_ids":["CWE-1333"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21490"},{"type":"PACKAGE","url":"https://github.com/angular/angular.js"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-6241746"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6241747"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113"},{"type":"WEB","url":"https://stackblitz.com/edit/angularjs-vulnerability-ng-srcset-redos"},{"type":"WEB","url":"https://support.herodevs.com/hc/en-us/articles/25715686953485-CVE-2024-21490-AngularJS-Regular-Expression-Denial-of-Service-ReDoS"}],"affected":[{"package":{"name":"angular","ecosystem":"npm","purl":"pkg:npm/angular"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.3.0"},{"last_affected":"1.8.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-4w4v-5hc9-xrr2/GHSA-4w4v-5hc9-xrr2.json"}},{"package":{"name":"org.webjars.npm:angular","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/angular"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.0"},{"last_affected":"1.8.3"}]}],"versions":["1.3.15","1.3.16","1.3.17","1.3.20","1.3.8","1.4.0","1.4.1","1.4.14","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5.0","1.5.0-beta.0","1.5.0-beta.2","1.5.0-rc.0","1.5.0-rc.1","1.5.0-rc.2","1.5.1","1.5.10","1.5.11","1.5.2","1.5.3","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.0-rc.2","1.6.1","1.6.10","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9","1.7.0","1.7.0-rc.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9","1.8.0","1.8.1","1.8.2","1.8.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-4w4v-5hc9-xrr2/GHSA-4w4v-5hc9-xrr2.json"}},{"package":{"name":"org.webjars.bower:angular","ecosystem":"Maven","purl":"pkg:maven/org.webjars.bower/angular"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.0"},{"last_affected":"1.8.3"}]}],"versions":["1.3.0","1.3.10","1.3.11","1.3.13","1.3.14","1.3.15","1.3.16","1.3.17","1.3.18","1.3.19","1.3.2","1.3.20","1.3.6","1.3.8","1.4.0","1.4.0-beta.5","1.4.0-beta.6","1.4.0-rc.1","1.4.0-rc.2","1.4.1","1.4.11","1.4.12","1.4.14","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","1.4.8","1.4.9","1.5.0","1.5.0-beta.0","1.5.0-beta.2","1.5.0-rc.0","1.5.0-rc.1","1.5.0-rc.2","1.5.1","1.5.10","1.5.11","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","1.6.0","1.6.0-rc.2","1.6.1","1.6.10","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.7-1","1.6.8","1.6.9","1.7.0","1.7.0-rc.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6","1.7.7","1.7.8","1.7.9","1.8.0","1.8.2","1.8.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-4w4v-5hc9-xrr2/GHSA-4w4v-5hc9-xrr2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}