← All CVEs NewScan detects
medium

CVE-2024-21490

AngularJS regular-expression denial of service via ng-srcset with untrusted input

Severity
medium
Affected product
Angular
Affected versions
Angular ≥ 1.3.0, ≤ 1.8.3
Fixed in
Angular no fix (EOL)
Added to NewScan
2026-07-30
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Angular from its response and reports this CVE when the detected version falls inside the affected range below.

Backfilled 2026-08-02 (docs/todo.md item 1).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →