Cross-site scripting in Angular - CVE-2026-27970

 

Cross-site scripting in Angular - CVE-2026-27970

Published: February 26, 2026


Vulnerability identifier: #VU123274
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-27970
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.

The vulnerability exists due to insufficient sanitization of user-supplied data in the Angular internationalization (i18n) pipeline. A remote attacker can pass specially crafted ICU messages to the application and execute arbitrary HTML and script code in user's browser in context of vulnerable website.



Affected software

Angular
IBM Sterling Connect:Direct Web Services
IBM Db2 Mirror for i
Storage Protect Client
Storage Protect for Space Management

How to mitigate CVE-2026-27970

Install updates from vendor's website.

Angular - addressed in versions 19.2.19, 20.3.17, 21.1.6, 21.2.0
IBM Sterling Connect:Direct Web Services - addressed in versions 6.3.0.19, 6.4.0.8
Storage Protect Client - update to 8.2.2.0
Storage Protect for Space Management - update to 8.2.2.0

External References

Related Security Bulletins