CRITICAL9.0CVE-2026-32635Angular vulnerable to XSS in i18n attribute bindings >= 22.0.0-next.0, < 22.0.0-next.3
MEDIUM6.1CVE-2026-54265@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS) >= 22.0.0-next.0, < 22.0.1
MEDIUM6.1CVE-2026-50557Angular: Template and Attribute Namespace Sanitization Bypass (XSS) >= 21.0.0-next.0, < 21.2.15
—Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
>= 21.1.0-next.0, < 21.1.0-rc.0
—Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes
>= 21.0.0-next.0, < 21.0.2