Executive brief
AngularJS is a JavaScript framework for building client-side web applications. A vulnerability in the locale formatting feature allows attackers to trigger a regular expression denial of service (ReDoS) by providing a specially crafted locale configuration, potentially causing the application to become unresponsive or crash. This affects applications using AngularJS version 1.7.0 and later.
Technical details
The vulnerability exists in AngularJS's locale formatting logic, specifically in the NUMBER_FORMATS.PATTERNS[1].posPre parameter handling. An attacker can provide a custom locale rule with an extremely high repetition count in the posPre field (via String.repeat()), which triggers catastrophic backtracking in the underlying regular expression engine, consuming excessive CPU resources. The attack vector is network-based and requires no authentication or user interaction; the malicious payload is supplied via locale configuration. This is a ReDoS (CWE-1333) vulnerability, causing denial of service without data compromise. AngularJS has been deprecated and no longer maintained, making patching unlikely.
Affected products
- Angular AngularJS 1.7.0 and later
Timeline
- 2022-05-01: disclosed
- 2022-05-03: advisory: GHSA-m2h2-264f-f486 published