FixVibe

high

AngularJS Regular Expression Denial of Service (CVE-2024-21490)

AngularJS 1.3.0 through 1.8.3 is affected by CVE-2024-21490, a regular-expression denial of service in ng-srcset handling. FixVibe GitHub repo scans flag affected AngularJS dependencies in npm, Bower, Maven and Gradle projects.

CVE-2024-21490GHSA-4w4v-5hc9-xrr2CWE-1333

Impact

Published advisories describe a Regular Expression Denial of Service issue in AngularJS ng-srcset parsing. AngularJS 1.3.0 through 1.8.3 can spend excessive CPU time when the affected parser processes large, carefully crafted srcset values [S1][S2]. Real customer impact depends on whether the affected AngularJS runtime is deployed and whether attacker-controlled data can reach an ng-srcset or equivalent srcset binding.

Affected package evidence

The reviewed GitHub Advisory lists the npm angular package and the Maven WebJars packages org.webjars.bower:angular and org.webjars.npm:angular as affected from 1.3.0 through 1.8.3, with no upstream patched AngularJS release [S1]. NVD also tracks CVE-2024-21490 with CWE-1333 and references AngularJS package evidence from version 1.3.0 onward [S2].

Remediation

AngularJS 1.x is end-of-life. The preferred remediation is to migrate to modern Angular through @angular/core, or to use a vendor-supported AngularJS distribution that explicitly covers CVE-2024-21490 [S1][S3]. Rebuild the deployed client bundle or WebJar-consuming application after updating dependency sources and lockfiles. While migration is planned, keep user-controlled values out of ng-srcset/srcset bindings and enforce conservative length and format validation at the component boundary.

How FixVibe covers it

FixVibe's GitHub repo scans flag npm, Bower, Maven and Gradle projects that resolve an AngularJS version affected by CVE-2024-21490 / GHSA-4w4v-5hc9-xrr2. The finding shows the package, version, file and line, with remediation guidance.