← Security Alerts

CVE-2026-11998

Google LLC · published 2026-06-24

Source record Collected from the National Vulnerability Database (NVD)

Description

Description by HeroDevs via the CVE Program.

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '<iframe>' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resource URLs. This issue affects AngularJS versions greater than or equal to 1.2.0-rc.3. Note: The AngularJS project was already End-of-Life when this CVE was published and will not receive any updates to address this issue. For more information see the  End-of-Life announcement https://docs.angularjs.org/misc/version-support-status .

Filed by HeroDevs; not a statement by Google LLC.

Status at the source

Affected products, as the source lists them

VendorProductVersions
GoogleAngularJS>=1.2.0-rc.3: affected

Added by redhat-SADP (Authorized Data Publisher)

VendorProductVersions
Red HatRed Hat Enterprise Linux 10—
Red HatRed Hat Enterprise Linux 10—
Red HatRed Hat Enterprise Linux 10—
Red HatRed Hat Enterprise Linux 10—
Red HatRed Hat Enterprise Linux 7—
Red HatRed Hat Enterprise Linux 8—
Red HatRed Hat Enterprise Linux 8—
Red HatRed Hat Enterprise Linux 8—
Red HatRed Hat Enterprise Linux 9—
Red HatRed Hat Enterprise Linux 9—
Red HatRed Hat Enterprise Linux 9—
Red HatRed Hat Enterprise Linux 9—
Red HatRed Hat Fuse 7—
Red HatRed Hat JBoss Enterprise Application Platform Expansion Pack—
Red HatRed Hat OpenStack Platform 16.2—
Red HatRed Hat Quay 3—
Red HatRed Hat Quay 3—
Red HatRed Hat Single Sign-On 7—

DeSpy has not checked any unit, hardware revision or firmware. A product missing here is not a statement that it is unaffected.

Scores, as their sources published them

DeSpy does not score records. These are the sources' own values.

Weaknesses

CWE-791, CWE-79

Sources

References the source lists

Source dates: published 2026-06-24, last changed 2026-08-05. DeSpy's copy of this version is dated 2026-09-28.

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE records: Copyright © 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE™). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

CISA's Known Exploited Vulnerabilities catalog and CISA Vulnrichment data are CC0 1.0. CISA advisories are shown with the TLP label their document carries. No endorsement by CISA, DHS, NIST or MITRE is stated or implied.

Scope, sources and licences →