CVE-2026-54267 — @angular/core
Fix: angular/angular@6bde84fCVE-2026-54267 is a Cross-site Scripting (XSS) vulnerability in @angular/core. A fix is available for @angular/core — see the affected versions and patch details below.
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
Exploitation Status
No confirmed exploitation observed yet
- A successful exploit gives an attacker total control of the affected component, not partial access.
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for CVE-2026-54267.
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
@angular/corenpmDescription
To optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports Hydration via provideClientHydration(). During SSR, Angular serializes the application's runtime state (such as cached HttpClient responses) and outputs it into the HTML stream as a <script> tag with a predictable identifier:
<script type="application/json" id="ng-state">
{"some-api-url": {"body": ...}}
</script>
During client bootstrap, Angular recovers this state by looking up the element via document.getElementById('ng-state') and parsing its text content.
Because the DOM element lookup for the state container is predictable and relies solely on the ID selector (ng-state), it is susceptible to DOM Clobbering.
If the application binds untrusted user input or CMS content to element properties such as id (e.g., <div [id]="userInput"> or <a id="ng-state">) before the genuine <script> tag is parsed by the browser, the attacker-controlled element takes precedence in the DOM lookup.
During hydration, when Angular calls document.getElementById('ng-state'), the browser returns the attacker's clobbered element. Angular then attempts to parse the text content or attributes of this clobbered element as JSON.
Impact
By clobbering the state element, the attacker can inject a custom JSON payload into Angular's TransferState cache. The most critical exploitation vector is poisoning the HTTP Transfer Cache.
- The attacker injects a clobbered
ng-stateelement containing custom JSON. - The JSON maps a key (representing a target API endpoint URL) to a malicious payload of the attacker's choice.
- During client-side initialization, Angular's
HttpClientchecksTransferStatebefore making requests. Finding the poisoned key,HttpClientreturns the forged response instantly instead of requesting the genuine backend API.
Depending on how the application processes and renders the affected API response, this can lead to:
- DOM-based Cross-Site Scripting (XSS) if poisoned fields are rendered using unsafe bindings.
- Privilege Escalation by spoofing user info or session details retrieved from poisoned API payloads.
- UI Hijacking and redirection by spoofing configuration endpoints.
Patched Versions
- 22.0.1
- 21.2.17
- 20.3.25
Workarounds
If you cannot immediately update to a patched Angular version, apply the following workarounds:
A. Avoid Dynamic/User-Controlled IDs
Avoid binding raw user-supplied values or dynamic CMS IDs directly to element attributes. If dynamic IDs are required, sanitize them or prepend a static safe prefix:
<!-- Vulnerable Pattern -->
<div [id]="userControlledInput">...</div>
<!-- Mitigated Pattern -->
<div [id]="'safe-prefix-' + userControlledInput">...</div>
B. Configure a Custom Application ID
Declaring a unique, non-predictable APP_ID changes the ID suffix of the state element, making it harder for attackers to predict and target:
// app.config.ts
import { APP_ID } from '@angular/core';
import { provideClientHydration } from '@angular/platform-browser';
export const appConfig = {
providers: [
{ provide: APP_ID, useValue: 'unique-obfuscated-app-id' },
provideClientHydration()
]
};
This changes the state element lookup ID from ng-state to unique-obfuscated-app-id-state.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | @angular/core | ≥ 22.0.0-next.0&&< 22.0.1 | 22.0.1npm install @angular/core@22.0.1 |
| 📦npm | @angular/core | ≥ 21.0.0-next.0&&< 21.2.17 | 21.2.17npm install @angular/core@21.2.17 |
| 📦npm | @angular/core | ≥ 20.0.0-next.0&&< 20.3.25 | 20.3.25npm install @angular/core@20.3.25 |
| 📦npm | @angular/core | all versions | No fix |
Affected Products
angularangularDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @angular/core, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update @angular/core to 22.0.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-54267 is resolved across your whole dependency graph.
Workarounds
Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
Red Hat products do not ship an @angular/core version within the vulnerable range (>= 22.0.0-next.0, < 22.0.1). Additionally, no Red Hat product ships or uses Angular's Server-Side Rendering hydration feature (@angular/platform-server, @angular/ssr, provideClientHydration()) that this vulnerability depends on.…
No mitigation is required. Red Hat products are not affected by this vulnerability, as detailed in the statement above.Source: Red Hat security advisory for CVE-2026-54267 (CC BY 4.0)
Frequently Asked Questions
Is CVE-2026-54267 in your dependencies?
Find it across npm, including transitive dependencies.