CVE-2026-27970: Angular Unvalidated Icu Attributes
HTML attributes parsed from ICU messages without bindings bypass validation and are unconditionally added to the DOM. This can allow attackers to inject malicious attributes (e.g., javascript: URIs) into translations.
greprules fetch cve-2026-27970-angular-unvalidated-icu-attributes --engine opengrepDescription
HTML attributes parsed from ICU messages without bindings bypass validation and are unconditionally added to the DOM. This can allow attackers to inject malicious attributes (e.g., javascript: URIs) into translations.
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.