REDHAT-BUG-2491459: XSS

Published Jun 22, 2026
·
Updated

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of <noscript> elements. When rendering dynamic text content inside a <noscript> element via template bindings (such as {{ value }} or [textContent]), the template engine expects the browser to render the content safely. Under Server-Side Rendering (SSR), domino is configured with scripting enabled, meaning <noscript> is treated as a raw-text element. However, domino's serializer completely omitted <noscript> from the list of raw-text elements requiring closing-tag escaping during DOM serialization. As a result, any occurrence of </noscript> in the bound dynamic text was never escaped under any circumstances. The unescaped closing tag was serialized directly into the output HTML (e.g. <noscript></noscript><script>alert(1)</script></noscript>). When parsed by a browser, it closes the <noscript> block early, allowing the injected <script> block to execute in the user's browser context, causing same-origin Cross-Site Scripting (XSS). This vulnerability is fixed in 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25.

Affected Software

1 affected component
npm/@angular/platform-server<22.0.0-rc.2, =21.2.16, =20.3.24, =19.2.25

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @angular/platform-server (domino DOM emulation dependency) to a version that resolves this vulnerability.

    Fixed in 22.0.0-rc.2
  2. Upgrade

    Upgrade @angular/platform-server (domino DOM emulation dependency) to a version that resolves this vulnerability.

    Fixed in 21.2.16
  3. Upgrade

    Upgrade @angular/platform-server (domino DOM emulation dependency) to a version that resolves this vulnerability.

    Fixed in 20.3.24
  4. Upgrade

    Upgrade @angular/platform-server (domino DOM emulation dependency) to a version that resolves this vulnerability.

    Fixed in 19.2.25

Event History

Jun 22, 2026
Data Sourced
via Red Hat·06:02 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2491459?

The severity of REDHAT-BUG-2491459 is high, rated at 7.

2

How does REDHAT-BUG-2491459 affect applications?

REDHAT-BUG-2491459 allows for Cross-Site Scripting (XSS) vulnerabilities in applications using affected Angular versions.

3

How do I fix REDHAT-BUG-2491459?

To fix REDHAT-BUG-2491459, upgrade to Angular versions 22.0.0-rc.2, 21.2.16, 20.3.24, or 19.2.25 or later.

4

Which versions of Angular are affected by REDHAT-BUG-2491459?

Versions prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25 are affected by REDHAT-BUG-2491459.

5

What type of vulnerability is REDHAT-BUG-2491459 classified as?

REDHAT-BUG-2491459 is classified as a Cross-Site Scripting (XSS) vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203