**Note:**
This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4242-1 | angular.js security update |
EUVD |
EUVD-2024-0512 | This affects versions of the package angular from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. **Note:** This package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core). |
Github GHSA |
GHSA-4w4v-5hc9-xrr2 | angular vulnerable to super-linear runtime due to backtracking |
Ubuntu USN |
USN-7958-1 | AngularJS vulnerabilities |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 16 Jan 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 10 Oct 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Angularjs
Angularjs angular.js |
|
| CPEs | cpe:2.3:a:angularjs:angular.js:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Angular
Angular angular |
Angularjs
Angularjs angular.js |
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-11-03T19:29:20.093Z
Reserved: 2023-12-22T12:33:20.118Z
Link: CVE-2024-21490
Updated: 2025-11-03T19:29:20.093Z
Status : Modified
Published: 2024-02-10T05:15:08.650
Modified: 2025-11-03T20:16:09.173
Link: CVE-2024-21490
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA
Ubuntu USN