Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-ff3f-86qr-9cv3
  • npm/@angular/router
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters 2 days ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-f67j-2jqw-jpq7
  • npm/@angular/platform-server
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE 4 days ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-j3r3-mxqp-r2p4
  • npm/@angular/platform-server
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements 4 days ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-v3p8-whq6-r5jg
  • npm/@angular/platform-server
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements 10 Sep
  • Fix available
  • Severity - 8.6 (High)
GHSA-f6mr-pjwc-34m4
  • npm/@angular/platform-server
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR 10 Sep
  • Fix available
  • Severity - 8.6 (High)
GHSA-p297-fm68-3q8c
  • npm/@angular/common
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` 10 Sep
  • Fix available
  • Severity - 4.0 (Medium)
GHSA-hh8m-fm6v-7cvg
  • npm/@angular/compiler
  • npm/@angular/core
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler 10 Sep
  • Fix available
  • Severity - 5.3 (Medium)
MAL-2026-15669
  • npm/kendo-angular-window
Malicious code in kendo-angular-window (npm) 01 Sep
  • No fix available
MAL-2026-14000
  • npm/blocks-angular
Malicious code in blocks-angular (npm) 13 Aug
  • No fix available
MAL-2026-12855
  • npm/bigops-watchdog-angular
Malicious code in bigops-watchdog-angular (npm) 05 Aug
  • No fix available
MAL-2026-12332
  • npm/@zahlen/checkout-angular
Malicious code in @zahlen/checkout-angular (npm) 05 Aug
  • No fix available
MAL-2026-12283
  • npm/tinkoff-ui-angular-addon-wysiwyg
Malicious code in tinkoff-ui-angular-addon-wysiwyg (npm) 05 Aug
  • No fix available
GHSA-jj27-h5hq-8x99
  • npm/@angular/compiler
  • npm/@angular/core
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes 03 Aug
  • Fix available
  • Severity - 7.6 (High)
GHSA-vpx6-8pjr-4g3v
  • npm/@angular/platform-server
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) 03 Aug
  • Fix available
  • Severity - 8.6 (High)
GHSA-jhpw-976m-542j
  • npm/@angular/common
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning 03 Aug
  • Fix available
  • Severity - 8.8 (High)
MAL-2026-11065
  • npm/swiper_angular
Malicious code in swiper_angular (npm) 25 Jul
  • No fix available