
🚨 New CVE Alert: CVE-2026-27970 — High-Severity XSS in Angular i18n A Cross-Site Scripting vulnerability has been identified in Angular’s internationalization (i18n) pipeline, where HTML inside translated ICU messages isn’t properly sanitized — allowing attacker-controlled JavaScript to execute in the application’s origin. This affects versions of @angular/core prior to the latest patched releases (including 19.2.19, 20.3.17, 21.1.6, and 21.2.0). In real-world terms: → If an attacker can compromise a translation file (like .xlf or .xtb), they can inject malicious attributes into ICU messages → When rendered, those attributes may execute arbitrary JavaScript in users’ browsers → This can lead to credential theft, session hijacking, or page manipulation If you’re maintaining Angular apps that use i18n, make sure you’re on a patched version today. And if you’re running Angular versions that have passed official support — or can’t upgrade right away — consider HeroDevs Never-Ending Support (NES) for Angular to receive ongoing security patches and compliance-ready fixes beyond upstream EOL. 🔗 https://www.herodevs.com/support/nes-angular #Angular #CVE #XSS #AppSec #OpenSourceSecurity #DevSecOps #HeroDevs
Post summary
A new high-severity XSS vulnerability (CVE-2026-27970) in Angular’s i18n pipeline has been disclosed with detailed exploitation vectors, existing patches, and guidance for updating or using third-party support for older versions.








