Angular's vulnerability profile centers on a prominent web application framework and its command-line tooling, both widely adopted in modern frontend development and therefore present across a large downstream ecosystem. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through input-handling weakness classes including cross-site scripting, open redirect, path traversal, and server-side request forgery that reflect the framework's role in rendering user-supplied content and handling HTTP interactions. Defenders should track this vendor's releases closely given the broad distribution of Angular applications and the potential for framework-level flaws to propagate to dependent projects; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Angular over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50178HIGH The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side Angular Language Service VS Code extension configures the t | Jun 22, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-49241HIGH The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4, the client-side Angular Language Service VS Code extension | Jun 22, 2026 | 8.8 | 34 | NO | NO |
CVE-2026-32635CRITICAL Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.3, 21.2.4, 20.3.18, and 19. | Mar 16, 2026 | 9.0 | 33 | NO | NO |
CVE-2026-50168HIGH Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2 | Jun 22, 2026 | 8.2 | 32 | NO | NO |
CVE-2026-54268HIGH Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial | Jun 22, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-50170HIGH Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2 | Jun 22, 2026 | 7.5 | 31 | NO | NO |
CVE-2026-50171MEDIUM Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2 | Jun 22, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-50556MEDIUM Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2 | Jun 22, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-54264MEDIUM Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an inform | Jun 22, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-54267MEDIUM Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, to optimi | Jun 22, 2026 | 6.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Angular.
Media articles that mention a CVE ID that affects a product developed by Angular — matched by CVE ID, not by vendor name.