CVE Explorer
CVE-2026-54268
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, which is also utilized by the standard Angular DatePipe, does not properly limit or validate the length of the format parameter. When parsing a maliciously crafted, excessively long date format string
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-1333","description":"CWE-1333: Inefficient Regular Expression Complexity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"angular","vendor":"angular","versions":[{"status":"affected","version":">= 22.0.0-next.0 < 22.0.1"},{"status":"affected","version":">= 21.0.0-next.0 < 21.2.17"},{"status":"affected","version":">= 20.0.0-next.0 < 20.3.25"},{"status":"affected","version":"<= 19.2.25"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":8.2,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
2 source assertions{"cweId":"CWE-400","description":"CWE-400: Uncontrolled Resource Consumption","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-1333","description":"CWE-1333: Inefficient Regular Expression Complexity","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"name":"https://github.com/angular/angular/commit/eeb03f4ea310e2e51ba5d53a421ec7b418e186cd","tags":["x_refsource_MISC"],"url":"https://github.com/angular/angular/commit/eeb03f4ea310e2e51ba5d53a421ec7b418e186cd"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/references/2
{"name":"https://github.com/angular/angular/pull/69197","tags":["x_refsource_MISC"],"url":"https://github.com/angular/angular/pull/69197"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/references/1
{"name":"https://github.com/angular/angular/security/advisories/GHSA-48r7-hpm6-gfxm","tags":["x_refsource_CONFIRM"],"url":"https://github.com/angular/angular/security/advisories/GHSA-48r7-hpm6-gfxm"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:6ac68fc51516b25cfcabfc2639687ae746585ef64d1785985f1b7db6b0caf408 · sha256:5dd8ab34279f0c47… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.