How to use this reference
Model every serialization and reparse boundary, including HTML post-processing. The linked remediation discussion shows that preserving comment semantics matters alongside escaping. The original advisory lists 22.0.7, 21.2.19 and 20.3.27 as fixes. Later advisories identify additional node and fragment cases, so these historical minimums do not establish comprehensive current remediation.
Before reading
- Server-side rendering and browser output-context concepts
- Basic trust-boundary and secure-input review
Context and limits
- Exposure requires SSR and untrusted content in the affected rendering context. Ordinary Angular use alone does not establish exposure. Avoiding those bindings or the implicated post-processing path are scoped workarounds, not universal guarantees.
- SkyZeroZx authored the linked remediation proposal on June 22, 2026; maintainer alan-agius4 merged it July 7. These are public-discussion and merge dates, not resource-edition or product-release dates.
- The August 27 follow-ups describe separate processing-instruction and document-fragment reachability limits; they list 22.1.4, 21.2.22 and 20.3.30 as patched and older unsupported branches as unpatched. These follow-ups limit the original patch claim without asserting that every initial deployment reached every later case.
- The processing-instruction advisory requires programmatic construction, unlike ordinary template syntax; the fragment advisory includes ordinary text-node cases. Both provide minimal demonstrations, but no production victim evidence.
Sources and provenance
- Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR Angular · reviewed 2026-10-03
- fix: escape fallback raw-content text nodes SkyZeroZx / Angular · reviewed 2026-10-03
- SSR XSS via Unescaped template Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements Angular · reviewed 2026-10-03
- SSR XSS via Unescaped Processing Instruction Nodes in Fallback Raw-Content Elements Angular · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.