CVE-2023-26116
MediumAdvisory
Published 30 Mar 2023In the index since 6 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.017
- 76th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 19
- of 17,781 indexed, latest versions
- Container images
- 14
- deployed by those charts
- Fix available
- None
- affected package
angular vulnerable to regular expression denial of service via the angular.copy() utility
Carried by container images the latest versions of 19 of 17,781 indexed charts deploy, on 14 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| angularnpm | 1.3.20, 1.5.3, 1.7.0, 1.7.8+4 more | no fix listed | 14 |
- OSV records
- GHSA-2vrf-hf26-jrp5
Charts affected
19 by stars
Container images carrying it
14 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| pantsel/ | c8172b75607d | angular | no fix listed | 3 |
| amazon/ | c740d7a89475 | angular | no fix listed | 2 |
| governify/ | daeca1ce28e6 | angular | no fix listed | 2 |
| opensearchproject/ | 39695180364b | angular | no fix listed | 2 |
| amazon/ | 5126e2e79a1f | angular | no fix listed | 1 |
| assistiot/ | 2297b4350211 | angular | no fix listed | 1 |
| kitware/ | d7767d9b9da4 | angular | no fix listed | 1 |
| konradkleine/ | 181aad54ee64 | angular | no fix listed | 1 |
| openemr/ | 89eaa6d9a4e3 | angular | no fix listed | 1 |
| opensearchproject/ | 485a0019e5d6 | angular | no fix listed | 1 |
| openthread/ | f307f59f6432 | angular | no fix listed | 1 |
| polonel/ | 0cf6513f6fe3 | angular | no fix listed | 1 |
| wazuh/ | 1787550d2358 | angular | no fix listed | 1 |
| quay.io/ | c973e166a5dc | angular | no fix listed | 1 |