Resource Exhaustion Affecting angular-codemirror package, versions *


Severity

Recommended
medium

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
5.3% (93rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL10-ANGULARCODEMIRROR-9889585
  • published28 Apr 2025
  • disclosed9 Oct 2020

Introduced: 9 Oct 2020

CVE-2020-7760  (opens in a new tab)
CWE-400  (opens in a new tab)

How to fix?

There is no fixed version for RHEL:10 angular-codemirror.

NVD Description

Note: Versions mentioned in the description apply only to the upstream angular-codemirror package and not the angular-codemirror package as distributed by RHEL. See How to fix? for RHEL:10 relevant fixed versions and status.

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/.?/)

CVSS Base Scores

version 3.1