Executive brief
Angular contains an insecure regular expression used to validate URL input fields. An attacker can send a carefully crafted malicious input to cause excessive CPU consumption and application slowdown, potentially disrupting service availability for legitimate users.
Technical details
This vulnerability is a Regular Expression Denial of Service (ReDoS) flaw affecting Angular's input[url] validation component. The vulnerable code uses an insecure regular expression that performs catastrophic backtracking when processing specially crafted input strings. The attack is network-reachable and requires no authentication or user interaction beyond submitting a malicious URL to a form field using the type="url" attribute. An attacker can trigger excessive CPU consumption, causing the application to hang or become unresponsive. All versions of Angular through 1.8.3 are affected.
Affected products
- Google Angular through 1.8.3
Timeline
- 2023-03-30: disclosed: Published in GitHub Advisory Database
- 2023-03-30: advisory: NVD published CVE-2023-26118