CVE-2026-11998Patch

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '<iframe>' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resource URLs. This issue affects AngularJS versions greater than or equal to 1.2.0-rc.3. Note: The AngularJS project was already End-of-Life when this CVE was published and will not receive any updates to address this issue. For more information see the  End-of-Life announcement https://docs.angularjs.org/misc/version-support-status .

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-791CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-26); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-26: 1Mentions · 2026-07-01: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-07-01: 106-2607-01
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Classification over time
DateTotalLabels
2026-06-261
Patch1
2026-07-011
Disclosure1
Full discourse2 posts
  • HeroDevs@herodevs
    Patch

    Nearly 5 years after AngularJS went end-of-life, we just found another High-severity CVE in it. 🚨 Not “saw it land in a feed.” Found it. George Kalpakas, Software Engineer at HeroDevs, discovered CVE-2026-11998 and we shipped the patch. That’s not luck. It’s what happens when the people maintaining your security coverage are the ones still actively looking at a framework everyone else walked away from. #AngularJS #AppSec #CVE #OpenSource #SoftwareSupplyChain

    Post summary

    A new high‐severity CVE (CVE‑2026‑11998) was discovered in AngularJS and promptly patched, with no exploits or active exploitation evidence provided.

    00030189
    2.7K followersView on X
  • HeroDevs@herodevs
    Disclosure

    CVE-2026-11998 just dropped in AngularJS: a High-severity XSS that bypasses Strict Contextual Escaping and lets attackers load arbitrary scripts in the user’s browser. AngularJS went EOL in December 2021. The Angular team will never patch this. We already did. #AngularJS #CyberSecurity #XSS #CVE #WebSecurity

    Post summary

    CVE-2026-11998 is a high‑severity XSS vulnerability in AngularJS that bypasses Strict Contextual Escaping; AngularJS is end‑of‑life and will not be patched.

    00000187
    2.7K followersView on X

Explore more