\n````\n\nDuring client bootstrap, Angular recovers this state by looki","image":"https://o3.security/opengraph.png","datePublished":"2026-06-15T15:16:18Z","dateModified":"2026-09-10T03:50:50.394914511Z","url":"https://o3.security/vulnerability/CVE-2026-54267","inLanguage":"en","author":{"@id":"https://o3.security/#organization"},"publisher":{"@id":"https://o3.security/#organization"},"mainEntityOfPage":{"@type":"WebPage","@id":"https://o3.security/vulnerability/CVE-2026-54267"},"speakable":{"@type":"SpeakableSpecification","cssSelector":["h1",".vuln-summary",".vuln-severity",".vuln-mitigation"]},"about":[{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm","softwareVersion":"22.0.1"},{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm","softwareVersion":"21.2.17"},{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm","softwareVersion":"20.3.25"},{"@type":"SoftwareApplication","name":"@angular/core","applicationCategory":"npm"}],"citation":[{"@type":"CreativeWork","name":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54267"},{"@type":"CreativeWork","name":"OSV.dev","url":"https://osv.dev/vulnerability/CVE-2026-54267"},{"@type":"CreativeWork","name":"FIRST.org EPSS","url":"https://www.first.org/epss/api-data?cve=CVE-2026-54267"},{"@type":"CreativeWork","url":"https://github.com/angular/angular/security/advisories/GHSA-rgjc-h3x7-9mwg"},{"@type":"CreativeWork","url":"https://github.com/angular/angular/pull/69064"},{"@type":"CreativeWork","url":"https://github.com/angular/angular/commit/6bde84fa8e6a5770b54040fbbc9bf10d5d0386fa"}]}\n````\n\nDuring client bootstrap, Angular recovers this state by looki","url":"https://o3.security/vulnerability/CVE-2026-54267","identifier":"CVE-2026-54267","datePublished":"2026-06-15T15:16:18Z","dateModified":"2026-09-10T03:50:50.394914511Z","inLanguage":"en","license":"https://creativecommons.org/licenses/by/4.0/","keywords":["CVE-2026-54267","MEDIUM severity","CWE-79","CWE-471","CVE","vulnerability","security advisory"],"creator":{"@id":"https://o3.security/#organization"},"isAccessibleForFree":true,"citation":[{"@type":"CreativeWork","name":"NVD","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54267"},{"@type":"CreativeWork","name":"OSV.dev","url":"https://osv.dev/vulnerability/CVE-2026-54267"},{"@type":"CreativeWork","name":"FIRST.org EPSS","url":"https://www.first.org/epss/api-data?cve=CVE-2026-54267"}],"variableMeasured":[{"@type":"PropertyValue","name":"CVSS Base Score","value":6.1,"description":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"@type":"PropertyValue","name":"Severity","value":"MEDIUM"},{"@type":"PropertyValue","name":"EPSS Percentile","value":22}]}\n````\n\nDuring client bootstrap, Angular recovers this state by looking up the element via `document.getElementById('ng-state')` and parsing its text content.\n\nBecause t"}},{"@type":"Question","name":"How severe is GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg has a CVSS score of 6.1/10, rated MEDIUM. Review your exposure and patch according to your risk tolerance."}},{"@type":"Question","name":"Which packages are affected by GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg affects the following packages: @angular/core (npm), @angular/core (npm), @angular/core (npm), @angular/core (npm). Ecosystems affected: npm."}},{"@type":"Question","name":"How do I fix GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"Update @angular/core to 22.0.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-rgjc-h3x7-9mwg is resolved across your whole dependency graph."}},{"@type":"Question","name":"How do I detect GHSA-rgjc-h3x7-9mwg in my npm dependencies?","acceptedAnswer":{"@type":"Answer","text":"Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @angular/core, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version."}},{"@type":"Question","name":"How do I mitigate GHSA-rgjc-h3x7-9mwg if there is no patch (or I can't update yet)?","acceptedAnswer":{"@type":"Answer","text":"Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page."}},{"@type":"Question","name":"Is GHSA-rgjc-h3x7-9mwg actively exploited in the wild?","acceptedAnswer":{"@type":"Answer","text":"No public exploit code has been indexed for GHSA-rgjc-h3x7-9mwg yet. This does not mean the vulnerability cannot be exploited — absence of public exploits does not imply safety. Apply the recommended fix and use O3 Security to monitor your exposure."}},{"@type":"Question","name":"What is the EPSS score for GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg has an EPSS (Exploit Prediction Scoring System) score of 0.3%, placing it in the 22th percentile of all CVEs. EPSS is maintained by FIRST.org and estimates the probability that a vulnerability will be exploited in the wild within the next 30 days. This score indicates relatively lower exploitation probability, though the CVSS severity should still guide your patching priority."}},{"@type":"Question","name":"What type of vulnerability is GHSA-rgjc-h3x7-9mwg?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg is classified as Cross-site Scripting (XSS) (CWE-79), CWE-471 (CWE-471). These weakness types describe the underlying flaw category, which helps determine the potential impact and the right class of mitigation. This is a high-impact weakness class that often enables remote code execution or data exposure."}},{"@type":"Question","name":"When was GHSA-rgjc-h3x7-9mwg published, and has it been updated?","acceptedAnswer":{"@type":"Answer","text":"GHSA-rgjc-h3x7-9mwg was published on June 15, 2026 and was last updated on September 10, 2026. Advisory data evolves as severity scores, affected ranges, and exploit intelligence are revised — always check the latest version of the advisory before acting."}}]}
Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
MEDIUM severity

GHSA-rgjc-h3x7-9mwg — @angular/core

MEDIUMFix: angular/angular#69064

GHSA-rgjc-h3x7-9mwg is a medium-severity (CVSS 6.1) Cross-site Scripting (XSS) vulnerability in @angular/core. A fix is available for @angular/core — see the affected versions and patch details below.

Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

Also known asCVE-2026-54267
Published
Jun 15, 2026
Updated
Sep 10, 2026
Affected
4 pkgs
Patched
3 / 4
Exploits
None indexed
Exploitation data as of Sep 26, 2026 · OSV.dev, NVD, FIRST.org (EPSS)

Exploitation Status

No confirmed exploitation observed yet

  • A successful exploit gives an attacker total control of the affected component, not partial access.
  • CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.

Exploitation and automatability from CISA’s SSVC triage for GHSA-rgjc-h3x7-9mwg.

EPSS Exploitation Probability

via FIRST.org ↗
0.3%probability of exploitation in next 30 days
Lower Risk0.00%
Lower risk than most CVEs22th percentile — riskier than 22% of all scored CVEsHighest risk

Probability of exploitation in the next 30 days, from FIRST.org EPSS.

How urgent is this, really

GHSA-rgjc-h3x7-9mwg by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.

Where this sits among everything scored

Of 379,842 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.

Real-World Exposure

4 pkgs affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

15Kother npm packages depend on this — each one inherits the vulnerability until it's patched upstream
@angular/corenpm
7.3Mdownloads / week

Description

To optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports Hydration via provideClientHydration(). During SSR, Angular serializes the application's runtime state (such as cached HttpClient responses) and outputs it into the HTML stream as a <script> tag with a predictable identifier:

<script type="application/json" id="ng-state">
    {"some-api-url": {"body": ...}}
</script>

During client bootstrap, Angular recovers this state by looking up the element via document.getElementById('ng-state') and parsing its text content.

Because the DOM element lookup for the state container is predictable and relies solely on the ID selector (ng-state), it is susceptible to DOM Clobbering.

If the application binds untrusted user input or CMS content to element properties such as id (e.g., <div [id]="userInput"> or <a id="ng-state">) before the genuine <script> tag is parsed by the browser, the attacker-controlled element takes precedence in the DOM lookup.

During hydration, when Angular calls document.getElementById('ng-state'), the browser returns the attacker's clobbered element. Angular then attempts to parse the text content or attributes of this clobbered element as JSON.

Impact

By clobbering the state element, the attacker can inject a custom JSON payload into Angular's TransferState cache. The most critical exploitation vector is poisoning the HTTP Transfer Cache.

  1. The attacker injects a clobbered ng-state element containing custom JSON.
  2. The JSON maps a key (representing a target API endpoint URL) to a malicious payload of the attacker's choice.
  3. During client-side initialization, Angular's HttpClient checks TransferState before making requests. Finding the poisoned key, HttpClient returns the forged response instantly instead of requesting the genuine backend API.

Depending on how the application processes and renders the affected API response, this can lead to:

  • DOM-based Cross-Site Scripting (XSS) if poisoned fields are rendered using unsafe bindings.
  • Privilege Escalation by spoofing user info or session details retrieved from poisoned API payloads.
  • UI Hijacking and redirection by spoofing configuration endpoints.

Patched Versions

  • 22.0.1
  • 21.2.17
  • 20.3.25

Workarounds

If you cannot immediately update to a patched Angular version, apply the following workarounds:

A. Avoid Dynamic/User-Controlled IDs

Avoid binding raw user-supplied values or dynamic CMS IDs directly to element attributes. If dynamic IDs are required, sanitize them or prepend a static safe prefix:

<!-- Vulnerable Pattern -->
<div [id]="userControlledInput">...</div>

<!-- Mitigated Pattern -->
<div [id]="'safe-prefix-' + userControlledInput">...</div>

B. Configure a Custom Application ID

Declaring a unique, non-predictable APP_ID changes the ID suffix of the state element, making it harder for attackers to predict and target:

// app.config.ts

import { APP_ID } from '@angular/core';
import { provideClientHydration } from '@angular/platform-browser';

export const appConfig = {
  providers: [
    { provide: APP_ID, useValue: 'unique-obfuscated-app-id' },
    provideClientHydration()
  ]
};

This changes the state element lookup ID from ng-state to unique-obfuscated-app-id-state.

Affected Packages

4 total 3 fixed
EcosystemPackageVulnerable rangeFix
📦npm@angular/core≥ 22.0.0-next.0&&< 22.0.122.0.1npm install @angular/core@22.0.1
📦npm@angular/core≥ 21.0.0-next.0&&< 21.2.1721.2.17npm install @angular/core@21.2.17
📦npm@angular/core≥ 20.0.0-next.0&&< 20.3.2520.3.25npm install @angular/core@20.3.25
📦npm@angular/coreall versionsNo fix

Affected Products

1 product · 4 configurations
Application
angularangular
≥ 22.0.0 && ≤ 19.2.25
range

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @angular/core, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.

  2. Fix

    Update @angular/core to 22.0.1 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-rgjc-h3x7-9mwg is resolved across your whole dependency graph.

  3. Workarounds

    Escape or sanitise the affected output on the server side rather than relying on client-side filtering, and add a Content-Security-Policy that blocks inline script execution so injected markup cannot run even if it reaches the page.

Fixing This On Your OS

If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.

Red HatModerate

Red Hat products do not ship an @angular/core version within the vulnerable range (>= 22.0.0-next.0, < 22.0.1). Additionally, no Red Hat product ships or uses Angular's Server-Side Rendering hydration feature (@angular/platform-server, @angular/ssr, provideClientHydration()) that this vulnerability depends on.…

Workaround published by Red Hat
No mitigation is required. Red Hat products are not affected by this vulnerability, as detailed in the statement above.
Source: Red Hat security advisory for GHSA-rgjc-h3x7-9mwg (CC BY 4.0)

Frequently Asked Questions

To optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports **Hydration** via `provideClientHydration()`. During SSR, Angular serializes the application's runtime state (such as cached `HttpClient` responses) and outputs it into the HTML stream as a `<script>` tag with a predictable identifier: ```html <script type="application/json" id="ng-state"> {"some-api-url": {"body": ...}} </script> ```` During client bootstrap, Angular recovers this state by looking up the element via `document.getElementById('ng-state')` and parsing its text content. Because t
O3 Security · Impact-Aware SCA

Is GHSA-rgjc-h3x7-9mwg in your dependencies?

Find it across npm, including transitive dependencies.

GHSA-rgjc-h3x7-9mwg: XSS (Medium 6.1) | O3 Security