目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-11998— Google AngularJS 输入验证错误漏洞

一分钟漏洞结论

影响对象
Google AngularJS
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Google AngularJS是美国Google公司的一款前端JavaScript框架。 Google AngularJS 1.2.0-rc.3版本及之后版本存在输入验证错误漏洞,该漏洞源于严格的上下文转义(SCE)逻辑中,用于将整个URL与正则表达式匹配器的正则表达式存在缺陷导致部分匹配,从而绕过资源URL的某些SCE策略,可能导致在受害者浏览器会话环境中执行任意JavaScript。

CVSS 7.6 · High EPSS 0.50% · P41

影响版本矩阵 1

厂商产品 版本范围状态
Google AngularJS >=1.2.0-rc.3 affected
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-11998 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
AngularJS XSS via SCE resource URL sanitization bypass
来源: CVE Program / CVE List V5
Vulnerability Description
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '<iframe>' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resource URLs. This issue affects AngularJS versions greater than or equal to 1.2.0-rc.3. Note: The AngularJS project was already End-of-Life when this CVE was published and will not receive any updates to address this issue. For more information see the  End-of-Life announcement https://docs.angularjs.org/misc/version-support-status .
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
特殊元素过滤不完全
来源: CVE Program / CVE List V5
Vulnerability Title
Google AngularJS 输入验证错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Google AngularJS是美国Google公司的一款前端JavaScript框架。 Google AngularJS 1.2.0-rc.3版本及之后版本存在输入验证错误漏洞,该漏洞源于严格的上下文转义(SCE)逻辑中,用于将整个URL与正则表达式匹配器的正则表达式存在缺陷导致部分匹配,从而绕过资源URL的某些SCE策略,可能导致在受害者浏览器会话环境中执行任意JavaScript。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Google AngularJS >=1.2.0-rc.3 -

二、漏洞 CVE-2026-11998 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-11998 的情报信息

请登录查看更多情报信息。

CVE-2026-11998 其他参考 (1)

同批安全公告 · Google · 2026-06-24 · 共 20 条

CVE-2026-13025 Google Chrome 输入验证错误漏洞
CVE-2026-12681 Google Go-Attestation 缓冲区错误漏洞
CVE-2026-13032 Google Chrome 资源管理错误漏洞
CVE-2026-13028 Google Chrome 资源管理错误漏洞
CVE-2026-13038 Google Chrome 资源管理错误漏洞
CVE-2026-13021 Google Chrome 输入验证错误漏洞
CVE-2026-13033 Google Chrome 缓冲区错误漏洞
CVE-2026-13022 Google Chrome 安全漏洞
CVE-2026-13023 Google Chrome 异常处理不当漏洞
CVE-2026-13026 Google Chrome 资源管理错误漏洞
CVE-2026-13036 Google Chrome 资源管理错误漏洞
CVE-2026-13024 Google Chrome 输入验证错误漏洞
CVE-2026-13029 Google Chrome 资源管理错误漏洞
CVE-2026-13027 Google Chrome 资源管理错误漏洞
CVE-2026-13031 Google Chrome 资源管理错误漏洞
CVE-2026-13034 Google Chrome 输入验证错误漏洞
CVE-2026-13030 Google Chrome 异常处理不当漏洞
CVE-2026-13037 Google Chrome 资源管理错误漏洞
CVE-2026-13035 Google Chrome 资源管理错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-11998

暂无评论


发表评论