Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

23 advisories

Loading
SkyZeroZx Credited to SkyZeroZx, josephperrott, alan-agius4, and JeanMeche josephperrott josephperrott
alan-agius4 alan-agius4 JeanMeche JeanMeche
@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker High
CVE-2026-54264 was published for @angular/service-worker (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, JeanMeche, and josephperrott alan-agius4 alan-agius4
JeanMeche JeanMeche josephperrott josephperrott
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate) High
CVE-2026-54268 was published for @angular/common (npm) Jun 15, 2026
JeanMeche Credited to JeanMeche, alan-agius4, SkyZeroZx, and josephperrott alan-agius4 alan-agius4
SkyZeroZx SkyZeroZx josephperrott josephperrott
alan-agius4 Credited to alan-agius4, JeanMeche, and josephperrott JeanMeche JeanMeche
josephperrott josephperrott
Angular: Template and Attribute Namespace Sanitization Bypass (XSS) Moderate
CVE-2026-50557 was published for @angular/compiler (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
josephperrott josephperrott AndrewKushnir AndrewKushnir
SkyZeroZx Credited to SkyZeroZx, alan-agius4, and josephperrott alan-agius4 alan-agius4
josephperrott josephperrott
@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High
CVE-2026-50555 was published for @angular/platform-server (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, and josephperrott alan-agius4 alan-agius4
josephperrott josephperrott
@angular/service-worker: Request Credential & Cache Policy Stripping Moderate
CVE-2026-50184 was published for @angular/service-worker (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, josephperrott, AndrewKushnir, alan-agius4, and JeanMeche josephperrott josephperrott
AndrewKushnir AndrewKushnir alan-agius4 alan-agius4 JeanMeche JeanMeche
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo) High
CVE-2026-50171 was published for @angular/common (npm) Jun 15, 2026
alan-agius4 Credited to alan-agius4, JeanMeche, AndrewKushnir, and josephperrott JeanMeche JeanMeche
AndrewKushnir AndrewKushnir josephperrott josephperrott
@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache High
CVE-2026-50170 was published for @angular/common (npm) Jun 15, 2026
Yenya030 Credited to Yenya030, josephperrott, alan-agius4, AndrewKushnir, and dgp1130 josephperrott josephperrott
alan-agius4 alan-agius4 AndrewKushnir AndrewKushnir dgp1130 dgp1130
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) Moderate
CVE-2026-52725 was published for @angular/core (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, AndrewKushnir, alan-agius4, and josephperrott AndrewKushnir AndrewKushnir
alan-agius4 alan-agius4 josephperrott josephperrott
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities Moderate
CVE-2026-50169 was published for @angular/service-worker (npm) Jun 15, 2026
Yenya030 Credited to Yenya030, alan-agius4, JeanMeche, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
JeanMeche JeanMeche josephperrott josephperrott AndrewKushnir AndrewKushnir
@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass High
CVE-2026-50168 was published for @angular/platform-server (npm) Jun 15, 2026
alan-agius4 Credited to alan-agius4, AndrewKushnir, josephperrott, and 0xEr3n AndrewKushnir AndrewKushnir
josephperrott josephperrott 0xEr3n 0xEr3n
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning High
CVE-2026-54267 was published for @angular/core (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, AndrewKushnir, alan-agius4, josephperrott, and JeanMeche AndrewKushnir AndrewKushnir
alan-agius4 alan-agius4 josephperrott josephperrott JeanMeche JeanMeche
Angular: SSRF via protocol-relative and backslash URLs in Angular Platform-Server High
CVE-2026-41423 was published for @angular/platform-server (npm) Apr 16, 2026
YLChen-007 Credited to YLChen-007, alan-agius4, AndrewKushnir, and josephperrott alan-agius4 alan-agius4
AndrewKushnir AndrewKushnir josephperrott josephperrott
Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR Moderate
CVE-2026-33397 was published for @angular/ssr (npm) Mar 19, 2026
VenkatKwest Credited to VenkatKwest, alan-agius4, securityMB, josephperrott, AndrewKushnir, and dgp1130 alan-agius4 alan-agius4
securityMB securityMB josephperrott josephperrott AndrewKushnir AndrewKushnir dgp1130 dgp1130
Angular vulnerable to XSS in i18n attribute bindings High
CVE-2026-32635 was published for @angular/compiler (npm) Mar 13, 2026
alan-agius4 Credited to alan-agius4, AndrewKushnir, securityMB, josephperrott, crisbeto, hdtmccallie, and VenkatKwest AndrewKushnir AndrewKushnir
securityMB securityMB josephperrott josephperrott crisbeto crisbeto hdtmccallie hdtmccallie VenkatKwest VenkatKwest
Angular i18n vulnerable to Cross-Site Scripting High
CVE-2026-27970 was published for @angular/core (npm) Feb 27, 2026
AndrewKushnir Credited to AndrewKushnir, josephperrott, alan-agius4, and dgp1130 josephperrott josephperrott
alan-agius4 alan-agius4 dgp1130 dgp1130
Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline Critical
CVE-2026-27739 was published for @angular/ssr (npm) Feb 25, 2026
Yenya030 Credited to Yenya030, alan-agius4, securityMB, AndrewKushnir, josephperrott, and dgp1130 alan-agius4 alan-agius4
securityMB securityMB AndrewKushnir AndrewKushnir josephperrott josephperrott dgp1130 dgp1130
Angular SSR has an Open Redirect via X-Forwarded-Prefix Moderate
CVE-2026-27738 was published for @angular/ssr (npm) Feb 25, 2026
alan-agius4 Credited to alan-agius4, josephperrott, securityMB, AndrewKushnir, dgp1130, and VenkatKwest josephperrott josephperrott
securityMB securityMB AndrewKushnir AndrewKushnir dgp1130 dgp1130 VenkatKwest VenkatKwest
Angular has XSS Vulnerability via Unsanitized SVG Script Attributes High
CVE-2026-22610 was published for @angular/compiler (npm) Jan 9, 2026
alan-agius4 Credited to alan-agius4, josephperrott, AndrewKushnir, jelbourn, hybrist, ShelbyKelley, and gkalpak josephperrott josephperrott
AndrewKushnir AndrewKushnir jelbourn jelbourn hybrist hybrist ShelbyKelley ShelbyKelley gkalpak gkalpak
Angular SSR has a Server-Side Request Forgery (SSRF) flaw High
CVE-2025-62427 was published for @angular/ssr (npm) Oct 16, 2025
meDavidNS Credited to meDavidNS, securityMB, hybrist, alan-agius4, and josephperrott securityMB securityMB
hybrist hybrist alan-agius4 alan-agius4 josephperrott josephperrott
Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage High
CVE-2025-59052 was published for @angular/platform-server (npm) Sep 10, 2025
alan-agius4 Credited to alan-agius4, jelbourn, josephperrott, thePunderWoman, atscott, and hybrist jelbourn jelbourn
josephperrott josephperrott thePunderWoman thePunderWoman atscott atscott hybrist hybrist
ProTip! Advisories are also available from the GraphQL API