DEBIAN-CVE-2026-11998

Source
https://security-tracker.debian.org/tracker/CVE-2026-11998
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-11998.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-11998
Upstream
Published
2026-06-24T21:16:52Z
Modified
2026-09-14T17:01:36Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L CVSS Calculator
Summary
[none]
Details

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '

References

Affected packages

Debian:12 / angular.js

Package

Name
angular.js
Purl
pkg:deb/debian/angular.js?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.3-1
1.8.3-1+deb12u1~deb11u1
1.8.3-1+deb12u1
1.8.3-2
1.8.3-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-11998.json"

Debian:13 / angular.js

Package

Name
angular.js
Purl
pkg:deb/debian/angular.js?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.3-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-11998.json"