Bug 2442934 (CVE-2026-27970)
| Summary: | CVE-2026-27970 @angular/core: Angular: Cross-site scripting via compromised translation files | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | alcohan, amctagga, aoconnor, bniver, flucifre, gmalinko, gmeno, gotiwari, gparvin, groman, janstey, jbalunas, jgrulich, jhorak, jkoehler, lphiri, mbenjamin, mhackett, mvyas, pahickey, pdelbell, rhaigner, rstepani, sostapov, tpopela, vereddy |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A Cross-Site Scripting (XSS) vulnerability has been identified in the Angular internationalization (i18n) pipeline. In ICU messages (International Components for Unicode), HTML from translated content was not properly sanitized and could execute arbitrary JavaScript. Angular i18n typically involves three steps, extracting all messages from an application in the source language, sending the messages to be translated, and then merging their translations back into the final source code. Translations are frequently handled by contracts with specific partner companies, and involve sending the source messages to a separate contractor before receiving final translations for display to the end user. If the returned translations have malicious content, it could be rendered into the application and execute arbitrary JavaScript.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2443073, 2443083, 2443084, 2443085, 2443091, 2443071, 2443072, 2443074, 2443075, 2443076, 2443077, 2443078, 2443079, 2443080, 2443081, 2443082, 2443086, 2443087, 2443088, 2443089, 2443090, 2443092 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-02-26 03:02:01 UTC
|