Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88057

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compiler could omit or select an incorrect sanitizer for security-sensitive directive host bindings because SecurityContext was derived from the declaring directive or component selector rather than the concrete host element. The mismatch is reachable through hostDirectives composition, inherited HostBinding declarations, createComponent with a custom hostElement or dynamic directives, SVG/MathML namespace elements, and tag-neutral selectors such as :not(...). Attacker-controlled href, src, action, xlink:href, or data values can therefore reach DOM attributes without Angular's built-in sanitizer and execute arbitrary JavaScript in the user's browser context. Applications unable to upgrade can use DomSanitizer.sanitize with SecurityContext.URL before assignment or restrict inputs to validated HTTP and HTTPS URL schemes. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.0.

A flaw was found in Angular's @angular/core and @angular/compiler components. This vulnerability allows a remote attacker to bypass security sanitization mechanisms. By injecting malicious data into specific HTML attributes, an attacker can cause the application to execute arbitrary JavaScript code in the user's browser, leading to a Cross-Site Scripting (XSS) attack. This occurs because the system incorrectly determines the security context for certain directive host bindings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-operator-bundleOut of support scope
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/volsync-rhel9Out of support scope
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-gitops-sync-rhel9Fix deferred
Red Hat build of Apicurio Registry 3apicurio/apicurio-registry-ui-rhel8Out of support scope
Red Hat Ceph Storage 4cephOut of support scope
Red Hat Enterprise Linux 10cephFix deferred
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10gjsFix deferred
Red Hat Enterprise Linux 10intel-cmt-catFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2531602@angular/core: @angular/compiler: Angular: Arbitrary code execution via sanitization bypass in host bindings

EPSS

Процентиль: 34%
0.00408
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

ubuntu
5 дней назад

(Angular is a development platform for building mobile and desktop web ...)

nvd
5 дней назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compiler could omit or select an incorrect sanitizer for security-sensitive directive host bindings because SecurityContext was derived from the declaring directive or component selector rather than the concrete host element. The mismatch is reachable through hostDirectives composition, inherited HostBinding declarations, createComponent with a custom hostElement or dynamic directives, SVG/MathML namespace elements, and tag-neutral selectors such as :not(...). Attacker-controlled href, src, action, xlink:href, or data values can therefore reach DOM attributes without Angular's built-in sanitizer and execute arbitrary JavaScript in the user's browser context. Applications unable to upgrade can use DomSanitizer.sanitize with SecurityContext.URL before assignme

debian
5 дней назад

Angular is a development platform for building mobile and desktop web ...

github
5 дней назад

Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler

EPSS

Процентиль: 34%
0.00408
Низкий

5.4 Medium

CVSS3