Junglewise Threat Intelligence

CVE-2023-26118: Angular regular expression denial of service in URL validation

CVE-2023-26118 · Severity: low · CVSS 3.1 · Published 2023-03-30

Technologies: angular (npm). Vendors: Google, npm.

Executive brief

Angular contains an insecure regular expression used to validate URL input fields. An attacker can send a carefully crafted malicious input to cause excessive CPU consumption and application slowdown, potentially disrupting service availability for legitimate users.

Technical details

This vulnerability is a Regular Expression Denial of Service (ReDoS) flaw affecting Angular's input[url] validation component. The vulnerable code uses an insecure regular expression that performs catastrophic backtracking when processing specially crafted input strings. The attack is network-reachable and requires no authentication or user interaction beyond submitting a malicious URL to a form field using the type="url" attribute. An attacker can trigger excessive CPU consumption, causing the application to hang or become unresponsive. All versions of Angular through 1.8.3 are affected.

Affected products

  • Google Angular through 1.8.3

Timeline

  • 2023-03-30: disclosed: Published in GitHub Advisory Database
  • 2023-03-30: advisory: NVD published CVE-2023-26118

References

Related threats