Medium · 5.3 React CVE-2026-88058 GHSA-j3r3-mxqp-r2p4 GHSA-v3p8-whq6-r5jg CVE-2026-88060
Angular Patches Five Vulnerabilities in SSR, Sanitization, and HTTP Caching
Angular has fixed five vulnerabilities affecting server-side rendering, directive sanitization, and HTTP transfer caching, including two high-severity XSS issues in @angular/platform-server and an SSRF flaw that could leak server-side credentials.
- NVD (NIST) database 1w ago · view ↗
- GitHub Advisory Database database 1w ago · view ↗
- GitHub Advisory Database database 1mo ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- CVE.org database 1mo ago · view ↗
- GitHub Advisory Database database 1mo ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- GitHub Advisory Database database 1mo ago · view ↗
- NVD (NIST) database 1w ago · view ↗
- GitHub Advisory Database database 1mo ago · view ↗
- NVD (NIST) database 1w ago · view ↗
AI summary
Angular has disclosed and fixed five separate vulnerabilities affecting its server-side rendering (SSR) pipeline, directive-based sanitization, and HTTP transfer caching. The issues span four packages: @angular/platform-server, @angular/common, @angular/core, and @angular/compiler. Three of the five involve cross-site scripting (XSS) conditions in SSR output, one is a server-side request forgery (SSRF) issue that can leak credentials, and one is an information disclosure issue related to cached HTTP responses. All five have been fixed by the Angular team in corresponding patch releases across the 20.x, 21.x, and 22.x lines.
What Happened
Angular's maintainers published five advisories affecting server-side rendering and related HTTP handling in @angular/platform-server, @angular/common, @angular/core, and @angular/compiler. CVE-2026-88058 and CVE-2026-88060 both describe SSR serialization flaws in @angular/platform-server where the Domino-based serializer fails to properly escape content inside 'fallback raw-content elements' such as noscript, iframe, noembed, and noframes. In CVE-2026-88058, ProcessingInstruction DOM nodes are serialized without escaping less-than characters that match an ancestor's closing tag, allowing premature termination of the container. In CVE-2026-88060, the serializer's traversal of fallbackRawContentTags stops at DocumentFragment boundaries used by <template> content, so closing tags nested inside template content (via xmp, style, script, comments, or text nodes) are not escaped either. CVE-2026-88056 is an SSRF issue: URL resolution utilities in @angular/platform-server (resolveUrl and parseUrl) call String.prototype.trim(), which strips certain Unicode whitespace characters after a same-origin check has already passed, turning a validated relative path into an attacker-controlled protocol-relative URL that HttpClient can then be made to request. CVE-2026-88057 is a sanitization bypass in @angular/core and @angular/compiler where SecurityContext for host bindings is derived from the declaring directive or component selector rather than the actual host element, which can cause the built-in sanitizer to be skipped or misapplied on security-sensitive attributes like href, src, action, or xlink:href. CVE-2026-88059 is an information-disclosure issue in @angular/common's HttpTransferCache, where a hierarchical HttpClient setup using withRequestsMadeViaParent can cause an authenticated response to be cached and later served, via shared SSR HTML, to a different unauthenticated or unauthorized visitor.
Technical Root Causes
The two SSR XSS issues (CVE-2026-88058, CVE-2026-88060) stem from incomplete escaping logic in the serializer Angular's SSR uses for fallback raw-content HTML elements. HTML5 RAWTEXT parsing rules mean a browser will treat any matching closing tag inside these elements as the actual end of the element, regardless of how it got there; if the serializer doesn't neutralize such sequences, trailing content is reinterpreted as live, executable markup. In CVE-2026-88058, this is reachable only through code using inject(DOCUMENT).createProcessingInstruction with attacker-controlled data, or Renderer2-based DOM insertion into one of these containers — not through standard Angular templates. In CVE-2026-88060, exposure depends on how content is authored: standard interpolation with comments or text nodes is reachable without relaxed schemas, literal xmp or style content requires CUSTOM_ELEMENTS_SCHEMA or NO_ERRORS_SCHEMA, and Renderer2-based DOM construction is unconditionally affected. The SSRF issue (CVE-2026-88056) arises because trim() removes certain Unicode whitespace characters (such as U+00A0 or U+FEFF) from a URL string only after that string has already passed a same-origin validation check, allowing a seemingly safe relative path to resolve to a different, attacker-controlled origin once trimmed. This matters specifically where relativeUrlsTransformerInterceptorFn forwards the request and the application attaches sensitive credentials such as Authorization headers. The sanitization bypass (CVE-2026-88057) occurs because Angular derives the SecurityContext used to pick a sanitizer from the declaring directive or component selector, not the concrete DOM element the binding ends up on; this mismatch can be triggered via hostDirectives composition, inherited HostBinding declarations, createComponent with a custom host element, SVG/MathML namespace elements, or tag-neutral selectors like :not(...). Finally, the HttpTransferCache issue (CVE-2026-88059) occurs because a child HttpClient evaluates a request as anonymous and caches it in TransferState before a parent interceptor chain (configured via withRequestsMadeViaParent) adds authentication headers; the parent-level cache correctly skips caching the authenticated request, but the child-level cache has already stored the private response, which is serialized into the page's ng-state script tag.
Why It Matters
The two SSR XSS vulnerabilities and the sanitization bypass can allow arbitrary JavaScript execution in a victim's browser, which can lead to session hijacking, credential theft, or further compromise of the affected web application. The SSRF vulnerability is particularly concerning for applications that attach server-side credentials (such as Authorization headers) to outgoing requests after URL validation, since it can result in those credentials being sent to an attacker-controlled destination. The HttpTransferCache issue can expose one user's authenticated response data to a later, unrelated visitor when SSR HTML is cached by a CDN, reverse proxy, or application-level cache, representing a cross-user information leak rather than code execution.
Who Is Affected
Organizations using Angular's server-side rendering capabilities via @angular/platform-server are affected by the two SSR XSS issues and the SSRF issue, though reachability varies: the ProcessingInstruction XSS (CVE-2026-88058) requires application or library code that explicitly creates ProcessingInstruction nodes or uses Renderer2 to insert DOM content into fallback raw-content elements; the template-content XSS (CVE-2026-88060) is reachable under varying conditions depending on whether relaxed schemas or Renderer2 are used; the SSRF issue (CVE-2026-88056) affects applications that validate URLs with WHATWG parsing and then route requests through HttpClient with credential-attaching interceptors. The sanitization bypass (CVE-2026-88057) affects applications using @angular/core and @angular/compiler with hostDirectives composition, inherited HostBinding declarations, dynamic component creation with custom host elements, or SVG/MathML content. The HttpTransferCache issue (CVE-2026-88059) affects applications using provideClientHydration together with a hierarchical HttpClient configuration via withRequestsMadeViaParent, where a parent interceptor adds credentials and SSR HTML responses are shared across users by a cache layer.
Affected Versions
For @angular/platform-server (CVE-2026-88058, CVE-2026-88060, CVE-2026-88056): versions up to and including 19.2.25, and versions from 20.0.0 before 20.3.30, from 21.0.0 before 21.2.22, and from 22.0.0 before 22.1.4 are affected. For @angular/core and @angular/compiler (CVE-2026-88057): versions up to and including 19.2.25, and versions from 20.0.0 before 20.3.28, from 21.0.0 before 21.2.20, and from 22.0.0 before 22.1.0 are affected. For @angular/common (CVE-2026-88059): versions up to and including 19.2.25, and versions from 20.0.0 before 20.3.28, from 21.0.0 before 21.2.20, and from 22.0.0 before 22.1.1 are affected.
Fixes and Mitigation
Angular has released fixes for all five issues. For @angular/platform-server, the fixes for CVE-2026-88058, CVE-2026-88060, and CVE-2026-88056 are included in versions 20.3.30, 21.2.22, and 22.1.4. For @angular/core and @angular/compiler, the fix for CVE-2026-88057 is included in versions 20.3.28, 21.2.20, and 22.1.0. For @angular/common, the fix for CVE-2026-88059 is included in versions 20.3.28, 21.2.20, and 22.1.1. For organizations unable to upgrade immediately, the advisory for CVE-2026-88057 notes that applications can mitigate by explicitly calling DomSanitizer.sanitize with SecurityContext.URL before assigning untrusted values, or by restricting such inputs to validated HTTP and HTTPS URL schemes. For CVE-2026-88059, applications can mitigate by attaching credentials at the child HttpClient rather than the parent, filtering sensitive endpoints with withHttpTransferCacheOptions, disabling transfer caching for sensitive routes, or marking personalized HTML responses as private or no-store. No specific interim mitigations beyond upgrading were described for CVE-2026-88058, CVE-2026-88060, or CVE-2026-88056.
Recommended Action
Review which of the four affected packages (@angular/platform-server, @angular/common, @angular/core, @angular/compiler) your application uses and upgrade to the corresponding fixed version: 20.3.30 / 21.2.22 / 22.1.4 for @angular/platform-server, 20.3.28 / 21.2.20 / 22.1.0 for @angular/core and @angular/compiler, and 20.3.28 / 21.2.20 / 22.1.1 for @angular/common. If immediate upgrades are not possible, apply the documented interim mitigations for the sanitization bypass and HttpTransferCache issues described above. Audit application and library code for use of inject(DOCUMENT).createProcessingInstruction, Renderer2-based DOM insertion into noscript/iframe/noembed/noframes elements, hierarchical HttpClient configurations using withRequestsMadeViaParent, and custom host-element or dynamic directive patterns, since these are the specific code paths that make these vulnerabilities reachable.
PatchBriefing score
5.3 / 10 · Medium
Official CVSS: 8.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
Three of the five vulnerabilities (CVE-2026-88058, CVE-2026-88060, CVE-2026-88056) carry a CVSS base score of 8.6, driven by high confidentiality and integrity impact combined with network-based, low-complexity attack vectors requiring no privileges, though user interaction is required. These map to a PatchBriefing score of 5.3, reflecting that a fix is available and there is no evidence of known exploitation or public exploit code, which keeps the overall score moderate despite the high CVSS base. CVE-2026-88057 has a lower CVSS base score of 5.3, reflecting its more limited confidentiality/integrity impact, yielding a PatchBriefing score of 3.5. CVE-2026-88059 has the lowest CVSS base score, 4.0, reflecting its low-confidentiality-impact, high-attack-complexity profile as an information disclosure issue, yielding a PatchBriefing score of 3.0. None of the five vulnerabilities are listed as known exploited, have public exploit code, or have an assigned EPSS exploitation probability score in this package.
Affected versions
- @angular/platform-server <= 19.2.25
- vulnerable
- ≥ 22.1.4
- patched
- ≥ 21.2.22
- patched
- ≥ 20.3.30
- patched
- @angular/platform-server <= 19.2.25
- vulnerable
- ≥ 22.1.4
- patched
- ≥ 21.2.22
- patched
- ≥ 20.3.30
- patched
- @angular/platform-server <= 19.2.25
- vulnerable
- ≥ 22.1.4
- patched
- ≥ 21.2.22
- patched
- ≥ 20.3.30
- patched
- @angular/common <= 19.2.25
- vulnerable
- ≥ 22.1.1
- patched
- ≥ 21.2.20
- patched
- ≥ 20.3.28
- patched
- @angular/core <= 19.2.25
- vulnerable
- ≥ 22.1.0
- patched
- ≥ 21.2.20
- patched
- ≥ 20.3.28
- patched
- @angular/compiler <= 19.2.25
- vulnerable
- ≥ 22.1.0
- patched
- ≥ 21.2.20
- patched
- ≥ 20.3.28
- patched
Reported fixes
Angular has released fixes for all five issues. For @angular/platform-server, the fixes for CVE-2026-88058, CVE-2026-88060, and CVE-2026-88056 are included in versions 20.3.30, 21.2.22, and 22.1.4. For @angular/core and @angular/compiler, the fix for CVE-2026-88057 is included in versions 20.3.28, 21.2.20, and 22.1.0. For @angular/common, the fix for CVE-2026-88059 is included in versions 20.3.28, 21.2.20, and 22.1.1. For organizations unable to upgrade immediately, the advisory for CVE-2026-88057 notes that applications can mitigate by explicitly calling DomSanitizer.sanitize with SecurityContext.URL before assigning untrusted values, or by restricting such inputs to validated HTTP and HTTPS URL schemes. For CVE-2026-88059, applications can mitigate by attaching credentials at the child HttpClient rather than the parent, filtering sensitive endpoints with withHttpTransferCacheOptions, disabling transfer caching for sensitive routes, or marking personalized HTML responses as private or no-store. No specific interim mitigations beyond upgrading were described for CVE-2026-88058, CVE-2026-88060, or CVE-2026-88056.
How this was built
11 source records were collected, matched and used to prepare the report above.
-
NVD (NIST) database
-
GitHub Advisory Database database
-
GitHub Advisory Database database
-
NVD (NIST) database
-
CVE.org database
-
GitHub Advisory Database database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email