Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27970

Опубликовано: 26 фев. 2026
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internationalization (i18n) pipeline. In ICU messages (International Components for Unicode), HTML from translated content was not properly sanitized and could execute arbitrary JavaScript. Angular i18n typically involves three steps, extracting all messages from an application in the source language, sending the messages to be translated, and then merging their translations back into the final source code. Translations are frequently handled by contracts with specific partner companies, and involve sending the source messages to a separate contractor before receiving final translations for display to the end user. If the returned translations have malicious content, it could be rendered into the application and execute arbitrary JavaScript. Whe

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
Версия до 19.2.19 (исключая)
cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
Версия от 20.0.0 (включая) до 20.3.17 (исключая)
cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
Версия от 21.0.0 (включая) до 21.1.6 (исключая)
cpe:2.3:a:angular:angular:21.2.0:next0:*:*:*:node.js:*:*
cpe:2.3:a:angular:angular:21.2.0:next1:*:*:*:node.js:*:*
cpe:2.3:a:angular:angular:21.2.0:next2:*:*:*:node.js:*:*
cpe:2.3:a:angular:angular:21.2.0:next3:*:*:*:node.js:*:*
cpe:2.3:a:angular:angular:21.2.0:rc0:*:*:*:node.js:*:*

EPSS

Процентиль: 13%
0.00044
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
30 дней назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internationalization (i18n) pipeline. In ICU messages (International Components for Unicode), HTML from translated content was not properly sanitized and could execute arbitrary JavaScript. Angular i18n typically involves three steps, extracting all messages from an application in the source language, sending the messages to be translated, and then merging their translations back into the final source code. Translations are frequently handled by contracts with specific partner companies, and involve sending the source messages to a separate contractor before receiving final translations for display to the end user. If the returned translations have malicious content, it could be rendered into the application and execute arbitrary JavaScript. ...

CVSS3: 7.1
redhat
30 дней назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Versions prior to 21.2.0, 21.1.16, 20.3.17, and 19.2.19 have a cross-Site scripting vulnerability in the Angular internationalization (i18n) pipeline. In ICU messages (International Components for Unicode), HTML from translated content was not properly sanitized and could execute arbitrary JavaScript. Angular i18n typically involves three steps, extracting all messages from an application in the source language, sending the messages to be translated, and then merging their translations back into the final source code. Translations are frequently handled by contracts with specific partner companies, and involve sending the source messages to a separate contractor before receiving final translations for display to the end user. If the returned translations have malicious content, it could be rendered into the application and execute arbitrary JavaScript. ...

CVSS3: 6.1
debian
30 дней назад

Angular is a development platform for building mobile and desktop web ...

CVSS3: 6.1
github
28 дней назад

Angular i18n vulnerable to Cross-Site Scripting

EPSS

Процентиль: 13%
0.00044
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79