Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-22610

Опубликовано: 10 янв. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG and xlink:href attributes within SVG <script> elements. This could allow an attacker to inject malicious scripts into web pages, leading to arbitrary code execution in the user's browser.

Отчет

This vulnerability is rated Moderate for Red Hat products. A cross-site scripting (XSS) flaw in the Angular Template Compiler allows an attacker to inject malicious scripts into web pages. This affects several Red Hat products, including Red Hat Enterprise Application Platform, Red Hat JBoss Fuse, Red Hat OpenStack Platform, Red Hat Quay, Red Hat Advanced Cluster Management for Kubernetes, and Red Hat Single Sign-On. Certain components within Red Hat Enterprise Linux and Community Projects are either not affected or will not be fixed.

Меры по смягчению последствий

This issue can be mitigating by avoiding the usage of dynamic bindings, this can be achieved by not using the Angular template binding [attr.href] when handling SVG <script> elements. If there's a need of using dynamic bindings, users are advised to validate the input against a strict list of trusted URLs on the server side before serving the values to the template.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Will not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10gjsNot affected
Red Hat Enterprise Linux 10grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2428424angular: Angular: Cross-site scripting vulnerability in Template Compiler

EPSS

Процентиль: 3%
0.00016
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG <script> elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.

CVSS3: 6.1
nvd
3 месяца назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0, a cross-site scripting (XSS) vulnerability has been identified in the Angular Template Compiler. The vulnerability exists because Angular’s internal sanitization schema fails to recognize the href and xlink:href attributes of SVG <script> elements as a Resource URL context. This issue has been patched in versions 19.2.18, 20.3.16, 21.0.7, and 21.1.0-rc.0.

CVSS3: 6.1
debian
3 месяца назад

Angular is a development platform for building mobile and desktop web ...

github
3 месяца назад

Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

EPSS

Процентиль: 3%
0.00016
Низкий

7.3 High

CVSS3