@angular/platform-server
npm7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @angular/platform-serverpage 1 of 1
- CVE-2025-59052HIGHCVSS 7.1EG 7.1✓ Fixed in 21.0.0-next.32025-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side ren…
- CVE-2026-41423MEDIUMCVSS 5.3EG 5.3✓ Fixed in 19.2.212026-05-08
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Server-Side Request Forgery (SSRF) vulnera…
- CVE-2026-46417MEDIUMCVSS 6.1EG 6.1✓ Fixed in 19.2.222026-05-19
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Side Request Forgery (SSRF) vulnerability …
- CVE-2026-50168HIGHCVSS 8.2EG 8.2✓ Fixed in 21.2.152026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allow…
- CVE-2026-50555MEDIUMCVSS 6.1EG 6.1✓ Fixed in 19.2.252026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @…
- CVE-2026-50556MEDIUMCVSS 6.1EG 6.1✓ Fixed in 19.2.252026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @…
- CVE-2026-69149MEDIUMCVSS 6.1EG 6.1✓ Fixed in 20.3.272026-08-03
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platfo…
Check whether @angular/platform-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @angular/platform-server CVEs against the assets you own.
Start Free Scan →