An open index of dependabot pull requests across open source projects.

@angular/common

Ecosystem:
npm
Package URL:
pkg:npm/@angular/common
Total PRs:
5,545 Dependabot PRs
Latest PR:
about 17 hours ago
Unique Repositories:
1,150 repositories
Unique Repos (30 days):
59 repositories
Security Advisories
@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
GHSA-48r7-hpm6-gfxm CVE-2026-54268 HIGH published 1 day ago • updated 1 day ago
A Denial of Service (DoS) vulnerability exists in the `@angular/common` package of the Angular framework. The `formatDate` function, which is also ...
@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
GHSA-39pv-4j6c-2g6v CVE-2026-54266 HIGH published 1 day ago • updated 1 day ago
Angular's `HttpTransferCache` caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration....
@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
GHSA-p3vc-36g9-x9gr CVE-2026-50171 HIGH published 1 day ago • updated 1 day ago
A Denial of Service (DoS) vulnerability exists in the `@angular/common` package of Angular. The `formatNumber` function, which is also utilized by ...
@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
GHSA-q6f4-qqrg-jv6x CVE-2026-50170 HIGH published 1 day ago • updated 1 day ago
A vulnerability was discovered in `@angular/common` when Server-Side Rendering (SSR) and hydration are enabled. The `HttpTransferCache` utility opt...
Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client
GHSA-58c5-g7wp-6w37 CVE-2025-66035 HIGH published 7 months ago • updated 3 days ago
The vulnerability is a **Credential Leak by App Logic** that leads to the **unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token*...
Recent PRs (filtered by: Open )
Package Details
Name: @angular/common
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/@angular/common
JSON API: View JSON
Security Advisories

5

Active advisories
HIGH 5
View All npm Advisories
Package Information
Description:

Angular - commonly needed directives and services

Repository: https://github.com/angular/angular
Homepage: https://github.com/angular/angular#readme
Latest Release: 20.0.1
about 1 year ago
Dependent Repos: 766,876
Dependent Packages: 24,687
Downloads: 15,506,737
Ranking: Top 0.0417% by dependent repos Top 0.0843% by downloads Top 0.005% by dependent pkgs
PR Status
Open 2,188 (39.5%)
Merged 852 (15.4%)
Closed 2,034 (36.7%)
PR Types
Major 1,603 (28.9%)
Minor 974 (17.6%)
Patch 2,497 (45.0%)