Impact
Published advisories describe a Regular Expression Denial of Service issue in AngularJS ng-srcset parsing. AngularJS 1.3.0 through 1.8.3 can spend excessive CPU time when the affected parser processes large, carefully crafted srcset values [S1][S2]. Real customer impact depends on whether the affected AngularJS runtime is deployed and whether attacker-controlled data can reach an ng-srcset or equivalent srcset binding.
Affected package evidence
The reviewed GitHub Advisory lists the npm angular package and the Maven WebJars packages org.webjars.bower:angular and org.webjars.npm:angular as affected from 1.3.0 through 1.8.3, with no upstream patched AngularJS release [S1]. NVD also tracks CVE-2024-21490 with CWE-1333 and references AngularJS package evidence from version 1.3.0 onward [S2].
Remediation
AngularJS 1.x is end-of-life. The preferred remediation is to migrate to modern Angular through @angular/core, or to use a vendor-supported AngularJS distribution that explicitly covers CVE-2024-21490 [S1][S3]. Rebuild the deployed client bundle or WebJar-consuming application after updating dependency sources and lockfiles. While migration is planned, keep user-controlled values out of ng-srcset/srcset bindings and enforce conservative length and format validation at the component boundary.
How FixVibe covers it
FixVibe's GitHub repo scans flag npm, Bower, Maven and Gradle projects that resolve an AngularJS version affected by CVE-2024-21490 / GHSA-4w4v-5hc9-xrr2. The finding shows the package, version, file and line, with remediation guidance.
