Cross-site scripting in Angular - CVE-2026-27970
Published: February 26, 2026
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data in the Angular internationalization (i18n) pipeline. A remote attacker can pass specially crafted ICU messages to the application and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Affected software
IBM Sterling Connect:Direct Web Services
IBM Db2 Mirror for i
Storage Protect Client
Storage Protect for Space Management
How to mitigate CVE-2026-27970
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Storage Protect Client - update to 8.2.2.0
Storage Protect for Space Management - update to 8.2.2.0