Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-v3p8-whq6-r5jg
  • npm/@angular/platform-server
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements 10 Sep
  • Fix available
  • Severity - 8.6 (High)
GHSA-f6mr-pjwc-34m4
  • npm/@angular/platform-server
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR 10 Sep
  • Fix available
  • Severity - 8.6 (High)
GHSA-p297-fm68-3q8c
  • npm/@angular/common
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` 10 Sep
  • Fix available
  • Severity - 4.0 (Medium)
GHSA-hh8m-fm6v-7cvg
  • npm/@angular/compiler
  • npm/@angular/core
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler 10 Sep
  • Fix available
  • Severity - 5.3 (Medium)
MAL-2026-15669
  • npm/kendo-angular-window
Malicious code in kendo-angular-window (npm) 01 Sep
  • No fix available
MAL-2026-14000
  • npm/blocks-angular
Malicious code in blocks-angular (npm) 13 Aug
  • No fix available
MAL-2026-12855
  • npm/bigops-watchdog-angular
Malicious code in bigops-watchdog-angular (npm) 05 Aug
  • No fix available
MAL-2026-12332
  • npm/@zahlen/checkout-angular
Malicious code in @zahlen/checkout-angular (npm) 05 Aug
  • No fix available
MAL-2026-12283
  • npm/tinkoff-ui-angular-addon-wysiwyg
Malicious code in tinkoff-ui-angular-addon-wysiwyg (npm) 05 Aug
  • No fix available
GHSA-jj27-h5hq-8x99
  • npm/@angular/compiler
  • npm/@angular/core
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes 03 Aug
  • Fix available
  • Severity - 7.6 (High)
GHSA-vpx6-8pjr-4g3v
  • npm/@angular/platform-server
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) 03 Aug
  • Fix available
  • Severity - 8.6 (High)
GHSA-jhpw-976m-542j
  • npm/@angular/common
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning 03 Aug
  • Fix available
  • Severity - 8.8 (High)
MAL-2026-11065
  • npm/swiper_angular
Malicious code in swiper_angular (npm) 25 Jul
  • No fix available
MAL-2026-10498
  • npm/eslint-angular-react
Malicious code in eslint-angular-react (npm) 13 Jul
  • No fix available
MAL-2026-6604
  • npm/@bodata/angular-client
Malicious code in @bodata/angular-client (npm) 29 Jun
  • No fix available
GHSA-7x27-g8rg-x87w
  • npm/angular
Angular's deprecated package has a Cross-Site Scripting issue 24 Jun
  • No fix available
  • Severity - 7.6 (High)