Angular 是一个用于使用 TypeScript/JavaScript 及其他语言构建移动和桌面 Web 应用的开发平台。在 20.3.30、21.2.22 和 22.1.4 版本之前,Angular 的服务端渲染(SSR,由 提供)会在像 、 、 和 这样的“回退型原始内容元素”(fallback raw-content elements)嵌套的模板内容中,序列化不可信输入。 问题根源在于:Domino 序列化器在遍历 时,会停止在由 使用的 处,导致 、 、 、HTML 注释或文本节点中的相应闭合标签未被转
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88058 | 8.6 HIGH | Angular: SSR XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Cont |
| CVE-2026-88056 | 8.6 HIGH | Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR |
| CVE-2026-88057 | 5.3 MEDIUM | Angular: Sanitization bypass via directive host bindings on concrete host elements in @ang |
| CVE-2026-88059 | 4.0 MEDIUM | Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaPa |
No comments yet