Angular是Angular组织开源的一个开发平台。用于使用 Typescript / JavaScript 和其他语言构建移动和桌面 Web 应用程序。 Angular存在跨站脚本漏洞,该漏洞源于动态组件创建过程中绕过脚本执行限制,可能导致未经身份验证的攻击者控制host元素或selector参数,在script标签上初始化或挂载Angular组件,从而执行未信任代码或客户端跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54265 | Angular: Two-Way Property Binding Sanitization Bypass (XSS) | |
| CVE-2026-54268 | Angular: Denial of Service (DoS) via OOM in Date Formatting (formatDate) | |
| CVE-2026-54266 | Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Dat | |
| CVE-2026-54264 | Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker | |
| CVE-2026-54267 | Angular Client Hydration DOM Clobbering & Response-Cache Poisoning | |
| CVE-2026-49241 | Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Cod | |
| CVE-2026-50171 | Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) | |
| CVE-2026-50169 | Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities | |
| CVE-2026-50557 | Angular: Template and Attribute Namespace Sanitization Bypass (XSS) | |
| CVE-2026-50168 | Angular: URL Parser Differential in @angular/platform-server leading to SSRF Allowlist Byp | |
| CVE-2026-50556 | Angular: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scriptin | |
| CVE-2026-50555 | Angular: Improper Neutralization of Input During Web Page Generation ('Cross-site Scriptin | |
| CVE-2026-50184 | Angular: Request Credential & Cache Policy Stripping in Angular Service Worker | |
| CVE-2026-50170 | Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCach | |
| CVE-2026-50178 | Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Langua | |
| CVE-2026-46417 | Angular: SSRF via Hostname Hijacking in @angular/platform-server |
No comments yet