{"id":"CVE-2024-21490","title":"This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0","summary":"This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. Wit…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-1333","CWE-1333"],"vendor":"angularjs","product":"angular.js","affected":["angular.js >= 1.3.0"],"published":"2024-02-10","updated":"2026-06-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-21490","references":[{"url":"https://security.snyk.io/vuln/SNYK-DOTNET-ANGULARJS-10771616","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-6241746","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6241747","label":"report@snyk.io"},{"url":"https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113","label":"report@snyk.io"},{"url":"https://stackblitz.com/edit/angularjs-vulnerability-ng-srcset-redos","label":"report@snyk.io"},{"url":"https://lists.debian.org/debian-lts-announce/2025/07/msg00005.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-6241746","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-6241747","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.snyk.io/vuln/SNYK-JS-ANGULAR-6091113","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://stackblitz.com/edit/angularjs-vulnerability-ng-srcset-redos","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://support.herodevs.com/hc/en-us/articles/25715686953485-CVE-2024-21490-AngularJS-Regular-Expression-Denial-of-Service-ReDoS","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01891,"epssPercentile":0.78693,"ingestedAt":"2026-06-29T21:48:47.192Z","exploits":{"github":1,"githubRepos":["https://github.com/RoninForge/roninforge-angularjs-migration"],"checkedAt":"2026-09-26T09:05:30.839Z"},"exploitAvailable":true,"slug":"CVE-2024-21490","body":"## Overview\n\nThis affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can result in catastrophic backtracking and cause a denial of service. \r\r\r**Note:**\r\rThis package is EOL and will not receive any updates to address this issue. Users should migrate to [@angular/core](https://www.npmjs.com/package/@angular/core).\n\n## Affected\n\n- `angular.js >= 1.3.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":41.3,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":4690,"id":"CVE-2024-21490","ts":1788887199864,"field":"exploit_available","old":"false","new":"true"},{"seq":3573,"id":"CVE-2024-21490","ts":1788886316354,"field":"exploit_available","old":"true","new":"false"},{"seq":2427,"id":"CVE-2024-21490","ts":1788882985102,"field":"exploit_available","old":"false","new":"true"},{"seq":1456,"id":"CVE-2024-21490","ts":1788882398379,"field":"exploit_available","old":"true","new":"false"},{"seq":570,"id":"CVE-2024-21490","ts":1788881834701,"field":"exploit_available","old":"false","new":"true"}]}