Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50171

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 5.9

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a Denial of Service (DoS) vulnerability exists in the @angular/common package of Angular. The formatNumber function, which is also utilized by DecimalPipe, PercentPipe, and CurrencyPipe, does not properly validate the upper bounds of the digitsInfo parameter. Specifically, the minimum and maximum fraction digits parsed from the digitsInfo string (e.g., 1.2-4) are converted to integers and used without limits. When parsing a maliciously crafted digitsInfo string with excessively large fraction digit values (e.g., 1.200000000-200000000), the internal roundNumber function attempts to pad the digits array to match the requested fraction size. This results in an unbounded loop that repeatedly pushes elements into an array. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

A flaw was found in the @angular/common package of Angular. The formatNumber function, which is also used by DecimalPipe, PercentPipe, and CurrencyPipe, does not properly validate the upper bounds of the digitsInfo parameter. A remote attacker could exploit this by providing a maliciously crafted digitsInfo string with excessively large fraction digit values. This leads to an unbounded loop, causing a Denial of Service (DoS) in the affected application.

Отчет

A flaw was found in the @angular/common package. The formatNumber function, also used by DecimalPipe, PercentPipe, and CurrencyPipe, does not validate the upper bounds of the digitsInfo parameter. When a maliciously crafted digitsInfo string with excessively large fraction digit values is provided, the internal roundNumber function enters an unbounded loop, causing a Denial of Service through memory exhaustion and CPU hang. Exploitation requires the application to pass user-controlled input to the digitsInfo parameter, which is not the default Angular usage pattern.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Upgrade to fixed versions or apply patches (ref: https://github.com/angular/angular/security/advisories/GHSA-p3vc-36g9-x9gr)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Not affected
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-ui-rhel8Not affected
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-ui-rhel9Not affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 10cephNot affected
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10gjsNot affected
Red Hat Enterprise Linux 10intel-cmt-catNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2491477@angular/common: Angular @angular/common: Denial of Service via malformed digitsInfo parameter

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 1 месяца назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a Denial of Service (DoS) vulnerability exists in the @angular/common package of Angular. The formatNumber function, which is also utilized by DecimalPipe, PercentPipe, and CurrencyPipe, does not properly validate the upper bounds of the digitsInfo parameter. Specifically, the minimum and maximum fraction digits parsed from the digitsInfo string (e.g., 1.2-4) are converted to integers and used without limits. When parsing a maliciously crafted digitsInfo string with excessively large fraction digit values (e.g., 1.200000000-200000000), the internal roundNumber function attempts to pad the digits array to match the requested fraction size. This results in an unbounded loop that repeatedly pushes elements into an array. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

CVSS3: 6.1
nvd
около 1 месяца назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a Denial of Service (DoS) vulnerability exists in the @angular/common package of Angular. The formatNumber function, which is also utilized by DecimalPipe, PercentPipe, and CurrencyPipe, does not properly validate the upper bounds of the digitsInfo parameter. Specifically, the minimum and maximum fraction digits parsed from the digitsInfo string (e.g., 1.2-4) are converted to integers and used without limits. When parsing a maliciously crafted digitsInfo string with excessively large fraction digit values (e.g., 1.200000000-200000000), the internal roundNumber function attempts to pad the digits array to match the requested fraction size. This results in an unbounded loop that repeatedly pushes elements into an array. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

CVSS3: 6.1
debian
около 1 месяца назад

Angular is a development platform for building mobile and desktop web ...

CVSS3: 6.1
github
около 2 месяцев назад

@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)

5.9 Medium

CVSS3