Angular 是一个用于使用 TypeScript/JavaScript 及其他语言构建移动端和桌面端 Web 应用的开发平台。 在 20.3.28、21.2.20 和 22.1.1 之前,Angular 的 中的 可能在特定条件下缓存经过身份验证的响应。该问题发生在同时启用服务端渲染(SSR)和水合(hydration),且使用通过 配置的分层 时。 具体场景如下: 1. 子级 TransferCache 在委派请求之前,先评估了一个初始的匿名请求。 2. 随后,父级的 拦截器链为请求添加了 Authoriza
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88058 | 8.6 HIGH | Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Cont |
| CVE-2026-88056 | 8.6 HIGH | Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR |
| CVE-2026-88060 | 8.6 HIGH | Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fa |
| CVE-2026-88057 | 5.3 MEDIUM | Angular: Sanitization bypass via directive host bindings on concrete host elements in @ang |
No comments yet