@angular/platform-server
npm11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @angular/platform-serverpage 1 of 1
- CVE-2025-59052HIGHCVSS 7.1EG 7.1fixed in 18.2.14, 20.3.0, 19.2.15 or 21.0.0-next.3, by version range2025-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side ren…
- CVE-2026-101895HIGHEG not assessedfixed in 22.1.6, 21.2.23 or 20.3.31, by version range2026-09-28
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE A Denial of Service (DoS) vulnerability exists in `@angular/platform-server`'s DOM emulation parser (`domino`). When processing untrusted user input containing an…
- CVE-2026-41423MEDIUMCVSS 5.3EG 5.3fixed in 22.0.0-next.8, 21.2.9, 20.3.19 or 19.2.21, by version range2026-05-08
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Server-Side Request Forgery (SSRF) vulnera…
- CVE-2026-46417MEDIUMCVSS 6.1EG 6.1fixed in 22.0.0-next.12, 21.2.13, 20.3.21 or 19.2.22, by version range2026-05-19
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Side Request Forgery (SSRF) vulnerability …
- CVE-2026-50168HIGHCVSS 8.2EG 8.2fixed in 22.0.0-rc.2, 20.3.22, 19.2.23 or 21.2.15, by version range2026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allow…
- CVE-2026-50555MEDIUMCVSS 6.1EG 6.1fixed in 22.0.0-rc.2, 21.2.16, 20.3.24 or 19.2.25, by version range2026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @…
- CVE-2026-50556MEDIUMCVSS 6.1EG 6.1fixed in 22.0.0-rc.2, 21.2.16, 20.3.24 or 19.2.25, by version range2026-06-15
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @…
- CVE-2026-69149MEDIUMCVSS 6.1EG 6.1fixed in 22.0.7, 21.2.19 or 20.3.27, by version range2026-08-03
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platfo…
- CVE-2026-88056CRITICALCVSS 9.1EG 9.1fixed in 22.1.4, 21.2.22 or 20.3.30, by version range2026-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes …
- CVE-2026-88058MEDIUMCVSS 6.1EG 6.1fixed in 22.1.4, 21.2.22 or 20.3.30, by version range2026-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server seri…
- CVE-2026-88060MEDIUMCVSS 6.1EG 6.1fixed in 22.1.4, 21.2.22 or 20.3.30, by version range2026-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server seri…
Check whether @angular/platform-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @angular/platform-server CVEs against the assets you own.
Book a Demo →