Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
Published Aug 3, 2026
8.6
HIGHCVSS 4.0
EPSS 0.42%
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of fallback raw-content elements (<iframe>, <noembed>, <noframes>, and <noscript>). This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.7.
Affected products
-
Affected
- < 20.3.27
- ≥ 21.0.0-next.0, < 21.2.19
- ≥ 22.0.0-next.0, < 22.0.7
- Vendor n/a Product Platform-Server Defaultunknown
Affected
- < 20.3.27
- ≥ 21.0.0-next.0, < 21.2.19
- ≥ 22.0.0-next.0, < 22.0.7
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No Red Hat product state for this CVE.
@angular/platform-server
npm
Introduced 21.0.0-next.0 Fixed 21.2.19@angular/platform-server
npm
Introduced 20.0.0-next.0 Fixed 20.3.27@angular/platform-server
npm
Introduced 0 Fixed not fixed@angular/platform-server
npm
Introduced 22.0.0-next.0 Fixed 22.0.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @angular/platform-server | 21.0.0-next.0 | 21.2.19 |
| npm | @angular/platform-server | 20.0.0-next.0 | 20.3.27 |
| npm | @angular/platform-server | 0 | not fixed |
| npm | @angular/platform-server | 22.0.0-next.0 | 22.0.7 |
Remediation
No remediation recorded yet.
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52350 Advisory
- https://github.com/advisories/GHSA-vpx6-8pjr-4g3v Advisory
- https://github.com/angular/angular/pull/69675 x_refsource_MISCIssue Tracking
- https://github.com/angular/angular/pull/69714 x_refsource_MISCIssue Tracking
- https://github.com/angular/angular/pull/69929 x_refsource_MISCIssue Tracking
- https://github.com/angular/angular/pull/69930 x_refsource_MISCIssue Tracking
- https://github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3v x_refsource_CONFIRMVendor AdvisoryMitigation
- https://github.com/angular/domino/commit/f88e5aa49cf2804d7c2df22ef1640eb4ec43dd56 x_refsource_MISCPatch
- https://github.com/angular/domino/pull/32 x_refsource_MISCIssue Tracking
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-52350 | Advisory | |
| https://github.com/advisories/GHSA-vpx6-8pjr-4g3v | Advisory | |
| https://github.com/angular/angular/pull/69675 | x_refsource_MISCIssue Tracking | |
| https://github.com/angular/angular/pull/69714 | x_refsource_MISCIssue Tracking | |
| https://github.com/angular/angular/pull/69929 | x_refsource_MISCIssue Tracking | |
| https://github.com/angular/angular/pull/69930 | x_refsource_MISCIssue Tracking | |
| https://github.com/angular/angular/security/advisories/GHSA-vpx6-8pjr-4g3v | x_refsource_CONFIRMVendor AdvisoryMitigation | |
| https://github.com/angular/domino/commit/f88e5aa49cf2804d7c2df22ef1640eb4ec43dd56 | x_refsource_MISCPatch | |
| https://github.com/angular/domino/pull/32 | x_refsource_MISCIssue Tracking |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub