CVE-2026-11998
published 2026-06-24CVE-2026-11998: A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript…
PriorityP342high7.6CVSS 3.1
AVNACLPRNUIRSUCHILAL
EPSS
0.34%
25.9th percentile
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resource URLs.
This issue affects AngularJS versions greater than or equal to 1.2.0-rc.3.
Note:
The AngularJS project was already End-of-Life when this CVE was published and will not receive any updates to address this issue. For more information see the End-of-Life announcement https://docs.angularjs.org/misc/version-support-status .
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angular | angular | — | — |
| angularjs | — | — | |
| grafana | grafana | — | — |
| mozilla | firefox | — | — |
| mozilla | thunderbird | — | — |
| quay | quay-rhel8 | — | — |
| quay | quay-rhel9 | — | — |
CVSS provenance
nvdv3.17.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
angularjs: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass
vendor_redhat·2026-06-24·CVSS 7.6
CVE-2026-11998 [HIGH] CWE-79 angularjs: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass
angularjs: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass
A flaw was found in AngularJS. The Strict Contextual Escaping (SCE) logic, designed to ensure only trusted values are used in security-sensitive contexts like resource URLs, can be bypassed. This bypass allows an attacker to use unsafe values as resource URLs, leading to arbitrary JavaScript execution within the victim's browser session. This could result in information disclosure or other impacts depending on the executed script.
Statement: An Important flaw in AngularJS's Strict Contextual Escaping (SCE) logic allows for a bypass, enabling arbitrary JavaScript execution within a victim's browser session. This vulnerability arises because the SCE's URL matching logic can be partially circ
GHSA
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's br
ghsa_unreviewed·2026-06-24
CVE-2026-11998 [HIGH] CWE-791 A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's br
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resource URLs.
This issue affects AngularJS versions greater than or equal to 1.2.0-rc.3.
Note:
The AngularJS project
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-11998 grafana: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 grafana: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 grafana: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A fla
Bugzilla
CVE-2026-11998 icecat: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 icecat: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 icecat: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A flaw
Bugzilla
CVE-2026-11998 mozjs140: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 mozjs140: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 mozjs140: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A fl
Bugzilla
CVE-2026-11998 vaultwarden-web: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [epel-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 vaultwarden-web: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [epel-all]
CVE-2026-11998 vaultwarden-web: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc.
Bugzilla
CVE-2026-11998 mozjs115: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 mozjs115: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 mozjs115: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A fl
Bugzilla
CVE-2026-11998 mozjs78: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [epel-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 mozjs78: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [epel-all]
CVE-2026-11998 mozjs78: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A flaw
Bugzilla
CVE-2026-11998 thunderbird: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 thunderbird: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 thunderbird: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A
Bugzilla
CVE-2026-11998 firefox: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 firefox: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 firefox: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A fla
Bugzilla
CVE-2026-11998 mozjs128: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 mozjs128: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 mozjs128: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A fl
Bugzilla
CVE-2026-11998 vaultwarden-web: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
bugzilla·2026-06-29·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 vaultwarden-web: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
CVE-2026-11998 vaultwarden-web: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, et
Bugzilla
CVE-2026-11998 angularjs: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass
bugzilla·2026-06-24·CVSS 7.6
CVE-2026-11998 [HIGH] CVE-2026-11998 angularjs: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass
CVE-2026-11998 angularjs: AngularJS: Arbitrary JavaScript execution due to Strict Contextual Escaping (SCE) bypass
A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.
SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resou
https://codepen.io/herodevs/pen/JobQdmz/5b3896f56fab66f20cd25e698cf3faa8https://www.herodevs.com/vulnerability-directory/cve-2026-11998https://access.redhat.com/security/cve/CVE-2026-11998https://bugzilla.redhat.com/show_bug.cgi?id=2492579https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-11998.jsonhttps://www.herodevs.com/vulnerability-directory/cve-2026-11998?nes-for-angularjs
2026-06-24
Published