Angular 是一个用于构建移动端和桌面端 Web 应用的开发平台,支持 TypeScript/JavaScript 及其他编程语言。 在 20.3.30、21.2.22 和 21.1.4 之前,Angular 的服务端渲染(Server-Side Rendering,@angular/platform-server)在处理由用户控制资源 URL 或请求 URL 时,会先通过应用代码使用 WHATWG URL 解析进行验证,随后再经由 HttpClient 处理。 被调用的 和 工具函数内部调用了 ,该调用会移除
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88058 | 8.6 HIGH | Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Cont |
| CVE-2026-88060 | 8.6 HIGH | Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fa |
| CVE-2026-88057 | 5.3 MEDIUM | Angular: Sanitization bypass via directive host bindings on concrete host elements in @ang |
| CVE-2026-88059 | 4.0 MEDIUM | Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaPa |
No comments yet