Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
Published Aug 3, 2026
7.6
HIGHCVSS 4.0
EPSS 0.33%
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.1, the Angular compiler i18n pipeline permits i18n-onerror and other i18n-on event-handler attributes, allowing a lower-trust translation file to replace a static handler with executable JavaScript. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.1.
Affected products
-
- Version < 20.3.27StatusaffectedConstraints-
- Version >= 21.0.0-next.0, < 21.2.19StatusaffectedConstraints-
- Version >= 22.0.0-next.0, < 22.0.1StatusaffectedConstraints-
- Version
- Vendor n/a Product Compiler Defaultn/a
- Version < 20.3.27StatusaffectedConstraints-
- Version >= 21.0.0-next.0, < 21.2.19StatusaffectedConstraints-
- Version >= 22.0.0-next.0, < 22.0.1StatusaffectedConstraints-
- Version
- Vendor n/a Product Core Defaultn/a
- Version < 20.3.27StatusaffectedConstraints-
- Version >= 21.0.0-next.0, < 21.2.19StatusaffectedConstraints-
- Version >= 22.0.0-next.0, < 22.0.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Angular | Angular | n/a |
| ||||||||||||
| n/a | Compiler | n/a |
| ||||||||||||
| n/a | Core | n/a |
|
No data.
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/volsync-operator-bundle
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/volsync-rhel9
Not affected
Red Hat Ceph Storage 4
ceph
Affected
Red Hat Enterprise Linux 10
ceph
Affected
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
gjs
Not affected
Red Hat Enterprise Linux 10
intel-cmt-cat
Affected
Red Hat Enterprise Linux 10
thunderbird
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
dotnet5.0-build-reference-packages
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
intel-cmt-cat
Affected
Red Hat Enterprise Linux 8
mozjs60
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
ceph
Affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
gjs
Not affected
Red Hat Enterprise Linux 9
intel-cmt-cat
Affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat build of Apicurio Registry 3
apicurio/apicurio-registry-ui-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-operator-bundle | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 4 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 10 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 10 | intel-cmt-cat | Affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet5.0-build-reference-packages | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | intel-cmt-cat | Affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | intel-cmt-cat | Affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat build of Apicurio Registry 3 | apicurio/apicurio-registry-ui-rhel8 | Not affected | n/a |
@angular/compiler
npm
Introduced 0 Fixed not fixed@angular/compiler
npm
Introduced 22.0.0-next.0 Fixed 22.0.1@angular/compiler
npm
Introduced 21.0.0-next.0 Fixed 21.2.19@angular/compiler
npm
Introduced 20.0.0-next.0 Fixed 20.3.27@angular/core
npm
Introduced 0 Fixed not fixed@angular/core
npm
Introduced 22.0.0-next.0 Fixed 22.0.1@angular/core
npm
Introduced 21.0.0-next.0 Fixed 21.2.19@angular/core
npm
Introduced 20.0.0-next.0 Fixed 20.3.27
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @angular/compiler | 0 | not fixed |
| npm | @angular/compiler | 22.0.0-next.0 | 22.0.1 |
| npm | @angular/compiler | 21.0.0-next.0 | 21.2.19 |
| npm | @angular/compiler | 20.0.0-next.0 | 20.3.27 |
| npm | @angular/core | 0 | not fixed |
| npm | @angular/core | 22.0.0-next.0 | 22.0.1 |
| npm | @angular/core | 21.0.0-next.0 | 21.2.19 |
| npm | @angular/core | 20.0.0-next.0 | 20.3.27 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 3, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 0.33% (0.00333) | 24.18th | v5 (v2026.06.15) |
| Aug 4, 2026 | 0.33% (0.00328) | 25.35th | v5 (v2026.06.15) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-69151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2510726 Issue Tracking
- https://github.com/advisories/GHSA-jj27-h5hq-8x99 Advisory
- https://github.com/angular/angular/commit/417a4071a776464d549509ed3aec121dbd2fda5e x_refsource_MISCPatch
- https://github.com/angular/angular/commit/6c41f5ca01c0ae045fc7d929b72853a11eb55865 x_refsource_MISCPatch
- https://github.com/angular/angular/pull/68821 x_refsource_MISCIssue Tracking
- https://github.com/angular/angular/pull/69306 x_refsource_MISCIssue Tracking
- https://github.com/angular/angular/security/advisories/GHSA-jj27-h5hq-8x99 x_refsource_CONFIRMMitigationVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-69151
- https://www.cve.org/CVERecord?id=CVE-2026-69151
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-69151 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2510726 | Issue Tracking | |
| https://github.com/advisories/GHSA-jj27-h5hq-8x99 | Advisory | |
| https://github.com/angular/angular/commit/417a4071a776464d549509ed3aec121dbd2fda5e | x_refsource_MISCPatch | |
| https://github.com/angular/angular/commit/6c41f5ca01c0ae045fc7d929b72853a11eb55865 | x_refsource_MISCPatch | |
| https://github.com/angular/angular/pull/68821 | x_refsource_MISCIssue Tracking | |
| https://github.com/angular/angular/pull/69306 | x_refsource_MISCIssue Tracking | |
| https://github.com/angular/angular/security/advisories/GHSA-jj27-h5hq-8x99 | x_refsource_CONFIRMMitigationVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-69151 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-69151 |
Change history (0)
No recorded changes yet.