Angular 19.x < 19.2.23 Multiple Vulnerabilities

high Web App Scanning Plugin ID 115607

Synopsis

Angular 19.x < 19.2.23 Multiple Vulnerabilities

Description

According to its self-reported version number, Angular is prior to 19.0.0, 19.x prior to 19.2.23, 20.x prior to 20.3.22 or 21.x prior to 21.2.15. It is, therefore, affected by multiple vulnerabilities:

- A sanitization bypass vulnerability in @angular/compiler and @angular/core. Namespaced script elements (such as <svg:script>) are not stripped during template compilation and attributes of namespaced elements are not consistently sanitized, leading to Cross-Site Scripting (XSS). (CVE-2026-50557)

- A request policy bypass vulnerability in @angular/service-worker. The credentials and cache modes defined by the client are stripped when requests are reconstructed, causing credentials to be sent on requests where they should be omitted and private resources to be cached. (CVE-2026-50184)

- A Server-Side Request Forgery (SSRF) vulnerability in @angular/platform-server. A URL parser differential between the WHATWG URL parser used for allowlist validation and the Domino URL parser allows a malformed URL (such as one with a double port) to bypass the allowedHosts check and direct server-side requests to an arbitrary host. (CVE-2026-50168)

- A protection bypass vulnerability in the dynamic component instantiation (createComponent) of @angular/core. Components can be mounted onto <script> or namespaced script elements, allowing an attacker controlling the host element or selector to execute arbitrary JavaScript, leading to Cross-Site Scripting (XSS). (CVE-2026-52725)

- A request redirect policy bypass vulnerability in @angular/service-worker. The redirect mode defined by the client is stripped when requests are reconstructed, causing HTTP redirects to be followed automatically and potentially exposing credentials or session-restricted data. (CVE-2026-50169)

- A denial of service vulnerability in the formatNumber function of @angular/common, also used by DecimalPipe, PercentPipe and CurrencyPipe. The fraction digits of the digitsInfo parameter are not bounded, allowing a crafted value to trigger an unbounded loop and memory exhaustion. (CVE-2026-50171)

- An information disclosure vulnerability in the HttpTransferCache of @angular/common when SSR and hydration are enabled. Credentialed requests are cached by default in the serialized transfer state, allowing a shared cache (such as a CDN) to leak private data of a user to other users. (CVE-2026-50170)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Angular version 19.2.23 or later.

See Also

https://github.com/angular/angular/security/advisories/GHSA-692r-grfm-v8x7

https://github.com/angular/angular/security/advisories/GHSA-95qp-cmmw-mgqv

https://github.com/angular/angular/security/advisories/GHSA-f3m7-gqxr-g87x

https://github.com/angular/angular/security/advisories/GHSA-gv2q-mqqv-365m

https://github.com/angular/angular/security/advisories/GHSA-p3vc-36g9-x9gr

https://github.com/angular/angular/security/advisories/GHSA-q6f4-qqrg-jv6x

https://github.com/angular/angular/security/advisories/GHSA-xrxm-cp7j-8xf6

Plugin Details

Severity: High

ID: 115607

Type: Version Based

Published: 10/2/2026

Updated: 10/2/2026

Scan Template: basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 3.5

Percentile: 51.98

CVSS v2

Risk Factor: High

Base Score: 8.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:P/A:N

CVSS Score Source: CVE-2026-50168

CVSS v3

Risk Factor: High

Base Score: 8.2

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CVSS Score Source: CVE-2026-50168

CVSS v4

Risk Factor: High

Base Score: 8.8

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: CVE-2026-50168

Vulnerability Information

CPE: cpe:2.3:a:angular:angular:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 6/7/2026

Reference Information

CVE: CVE-2026-50168, CVE-2026-50169, CVE-2026-50170, CVE-2026-50171, CVE-2026-50184, CVE-2026-50557, CVE-2026-52725

CWE: 200, 346, 400, 441, 524, 79, 834, 918

OWASP: 2010-A2, 2010-A6, 2013-A3, 2013-A5, 2013-A9, 2017-A6, 2017-A7, 2017-A9, 2021-A1, 2021-A10, 2021-A3, 2021-A6, 2021-A7, 2025-A1, 2025-A5, 2025-A6, 2025-A7

WASC: Application Misconfiguration, Cross-Site Scripting, Denial of Service, Information Leakage

CAPEC: 111, 116, 13, 141, 142, 147, 160, 169, 197, 209, 21, 22, 224, 285, 287, 290, 291, 292, 293, 294, 295, 296, 297, 298, 299, 300, 301, 302, 303, 304, 305, 306, 307, 308, 309, 310, 312, 313, 317, 318, 319, 320, 321, 322, 323, 324, 325, 326, 327, 328, 329, 330, 384, 385, 386, 387, 388, 472, 492, 497, 508, 510, 573, 574, 575, 576, 577, 588, 59, 591, 592, 60, 616, 63, 643, 646, 651, 75, 76, 79, 85, 89

DISA STIG: APSC-DV-000460, APSC-DV-002400, APSC-DV-002490, APSC-DV-002560, APSC-DV-002630

HIPAA: 164.306(a)(1), 164.306(a)(2)

ISO: 27001-A.10.1, 27001-A.12.6.1, 27001-A.14.2.5

NIST: sp800_53-CM-6b, sp800_53-SC-5, sp800_53-SI-10, sp800_53-SI-10(5), sp800_53-SI-15

OWASP API: 2019-API7, 2023-API7, 2023-API8

OWASP ASVS: 4.0.2-14.2.1, 4.0.2-14.4.7, 4.0.2-5.2.6, 4.0.2-5.3.3, 4.0.2-8.3.4

PCI-DSS: 3.2-2.2, 3.2-6.2, 3.2-6.5.7, 3.2-6.5.8, 3.2-6.5.9