Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54268

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, which is also utilized by the standard Angular DatePipe, does not properly limit or validate the length of the format parameter. When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS). This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.

A flaw was found in the @angular/common package of the Angular framework. A remote attacker could exploit a Denial of Service (DoS) vulnerability in the formatDate function, which is also used by the Angular DatePipe, by providing an excessively long and maliciously crafted date format string. This improper validation of the format parameter's length leads to uncontrolled resource consumption, such as high CPU utilization and excessive memory allocations, ultimately resulting in a Denial of Service for the affected application.

Отчет

A flaw was found in Angular's @angular/common DatePipe. A crafted date format string can cause excessive CPU consumption, resulting in a denial of service. Red Hat Integration Service Registry includes @angular/common in its UI components and is affected by this vulnerability. Most other Red Hat products matched by SBOM scanning (Firefox, Thunderbird, SpiderMonkey, Ceph, GJS, syncthing, intel-cmt-cat) do not use the Angular framework and are not affected.

Меры по смягчению последствий

Validate and sanitize user-supplied date format strings before passing them to Angular's DatePipe. Implement request rate limiting and timeouts on web application endpoints to limit the impact of malicious requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleNot affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Not affected
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-ui-rhel8Not affected
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-ui-rhel9Not affected
Red Hat Ceph Storage 4cephNot affected
Red Hat Enterprise Linux 10cephNot affected
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10gjsNot affected
Red Hat Enterprise Linux 10intel-cmt-catNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2491411@angular/common: Angular @angular/common: Denial of Service via crafted date format string

EPSS

Процентиль: 25%
0.00327
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, which is also utilized by the standard Angular DatePipe, does not properly limit or validate the length of the format parameter. When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS). This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.

CVSS3: 7.5
nvd
около 1 месяца назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, which is also utilized by the standard Angular DatePipe, does not properly limit or validate the length of the format parameter. When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS). This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.

CVSS3: 7.5
debian
около 1 месяца назад

Angular is a development platform for building mobile and desktop web ...

CVSS3: 7.5
github
около 2 месяцев назад

@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

EPSS

Процентиль: 25%
0.00327
Низкий

5.3 Medium

CVSS3