Visit AngularJS NES Home Page
AngularJS 1.8.x-1.9.x Release Notes
Comprehensive release notes and changelog for AngularJS 1.8.x-1.9.x, including security patches, bug fixes, and feature updates across all supported versions.
14 Patched Vulnerabilities
VEX Statements
AngularJS
1.9.12 (NES/XLTS) - June 17, 2026
Notes
- Full package name(s) and version(s):
@neverendingsupport/angularjs@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-animate@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-aria@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-cookies@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-i18n@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-loader@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-message-format@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-messages@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-mocks@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-parse-ext@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-resource@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-route@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-sanitize@1.8.3-angularjs-1.9.12@neverendingsupport/angularjs-touch@1.8.3-angularjs-1.9.12
Security & Compatibility Fixes
- $sceDelegate:
- Always apply resource URL matchers to entire URL.
- This fixes a high-severity Cross-Site Scripting (XSS) vulnerability (CVE-2026-11998).
- Always apply resource URL matchers to entire URL.
1.9.11 (NES/XLTS) - September 19, 2025
Notes
- This release contains no functional changes from NES v1.9.10.
- This release implements a new package naming scheme for the AngularJS packages. More information about the change can be found in the NES Decoupled Namespace Specification.
- Full package name(s) and version(s):
@neverendingsupport/angularjs@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-animate@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-aria@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-cookies@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-i18n@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-loader@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-message-format@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-messages@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-mocks@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-parse-ext@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-resource@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-route@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-sanitize@1.8.3-angularjs-1.9.11@neverendingsupport/angularjs-touch@1.8.3-angularjs-1.9.11
1.9.10 (NES/XLTS) - May 28, 2025
Notes
Note
Although some of the bug fixes in this release are not for exploitable vulnerabilities, we are making the changes out of an abundance of caution and to proactively avoid incorrect flagging in SAST scans.
Security & Compatibility Fixes
- $compile:
- Improve performance of
srcsetattribute sanitization. - Improve performance of comment-based directive collection.
- Improve performance of
- $injector:
- Improve performance of implicit dependency annotation.
- linky:
- Prevent ReDoS when searching for URLs in text.
- This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2025-4690).
- Prevent ReDoS when searching for URLs in text.
- ngMocks:
- Improve performance of trailing slash removal in
$httpBackend.
- Improve performance of trailing slash removal in
1.9.9 (NES/XLTS) - March 19, 2025
Security & Compatibility Fixes
- $sanitize:
- Sanitize image sources on
<image>SVG elements.- This fixes a medium-severity Content Spoofing vulnerability (CVE-2025-2336).
- Sanitize image sources on
1.9.8 (NES/XLTS) - February 18, 2025
Security & Compatibility Fixes
- $compile:
- Always sanitize image sources on
<image>SVG element.- This fixes a medium-severity Content Spoofing vulnerability (CVE-2025-0716).
- Always sanitize image sources on
Breaking Changes
$compile
- Always sanitize image sources on
<image>SVG element:
In the unlikely case that an app relied on trusted$sce.RESOURCE_URLvalues, via$sceDelegateProvider.trustedResourceUrlList()/$sceDelegateProvider.resourceUrlWhitelist()or$sce.trustAs($sce.RESOURCE_URL, ...)or$sce.trustAsResourceUrl(), for the purpose of binding to thexlink:hrefproperty of<image>SVG elements and if the values do not pass the regular image URL sanitization, the affected SVG images will not be rendered.
To fix this, you need to ensure that the values used for binding to thexlink:hrefattributes of<image>SVG elements are considered safe image URLs, via$compileProvider.imgSrcSanitizationTrustedUrlList().
Before:angular .module('myApp') .config(['$sceDelegateProvider', $sceDelegateProvider => { $sceDelegateProvider.trustedResourceUrlList([ // ...other resource URLs... // Allow resource URLs from `https://my.domain.com/images/` // for the purpose of using with `image[xlink:href]`. /https:\/\/my\.domain\.com\/images\/.*/, ]); }]); // ...or... angular .module('myApp') .run(['$rootScope', '$sce', ($rootScope, $sce) => { // Trust a specific URL as a resource URL for the purpose // of using in templates with `image[xlink:href]`. $rootScope.trustedImageUrl = $sce.trustAsResourceUrl( 'https://my.domain.com/images/some-image.png'); }]);
After:angular .module('myApp') .config([ '$compileProvider', '$sceDelegateProvider', ($compileProvider, $sceDelegateProvider) => { $sceDelegateProvider.trustedResourceUrlList([ // ...other resource URLs... ]); $compileProvider.imgSrcSanitizationTrustedUrlList( // Allow image URLs from `https://my.domain.com/images/` // for the purpose of using with `<img>` or `<image>`. /^https:\/\/my\.domain\.com\/images\//, // ...or... // Trust specific URLs as image URLs for the purpose // of using in templates with `<img>` or `<image>`. /^https:\/\/my\.domain\.com\/images\/(?:some-image\.png|other-image\.jpg)$/, ); }, ]);
1.9.7 (NES/XLTS) - July 18, 2024
Notes
- This release contains some metadata fixes and improvements:
- Preserve license file headers in minified files.
- Use correct names and versions in
bower.jsonfiles.
Security & Compatibility Fixes
- jqLite:
- Add opt-in mode for compatibility with jQuery v4 via
angular.jqLite_jQueryLt4CompatibilityEnabled().- See Compatibility with jQuery v4 for more information.
- Add opt-in mode for compatibility with jQuery v4 via
1.9.6 (NES/XLTS) - May 21, 2024
Security & Compatibility Fixes
- $compile:
- Always sanitize image sources on
<source>element.- This fixes a medium-severity Content Spoofing vulnerability (CVE-2024-8373).
- Always sanitize image sources on
- srcset:
- Prevent bypassing image source sanitization with
(ng(Attr))Srcset.- This fixes a medium-severity Content Spoofing vulnerability (CVE-2024-8372).
- Prevent bypassing image source sanitization with
1.9.5 (NES) - February 4, 2024
Notes
- This release contains no functional changes from NES v1.9.4.
- This release contains only metadata fixes and improvements: Fixed deployment script that resulted in v1.9.4 incorrectly registering as v1.9.5-local+sha.6756ba9 in various places (code headers,
angularglobal object, etc.).
1.9.4 (NES) - October 22, 2023
Notes
- Repackaging XLTS for AngularJS as AngularJS NES
- XLTS merged with HeroDevs in September 2023 and continues to support AngularJS under Never-Ending Support (NES).
- AngularJS NES v1.5.21 is functionally equivalent to XLTS for AngularJS v1.5.19.
1.9.3 (XLTS) - August 18, 2023
Security & Compatibility Fixes
- $compile:
- Fix a possible ReDoS in
ng-srcsetparsing.- This fixes a high-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2024-21490).
- Fix a possible ReDoS in
- route:
- Suppress warning from CodeQL regarding escaping backslash characters.
1.9.2 (XLTS) - July 12, 2023
Security & Compatibility Fixes
- ngAnimate:
- Make animation duration calculation compatible with CSS Animations Level 2.
- browserTrigger:
- Fix focus triggering in IE with jQuery >=3.7.0.
- bootstrap:
- No longer trigger
RegExpwarning in CodeQL scans.
- No longer trigger
1.9.1 (XLTS) - April 4, 2023
Security & Compatibility Fixes
- $compile:
- Fix
mergeConsecutiveTextNodeslogic for jQuery v4 preview.
- Fix
- $resource:
- Avoid DoS in stripping trailing slashes.
- This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2023-26117).
- Avoid DoS in stripping trailing slashes.
- Angular:
- Collect jQuery nodes between two elements correctly for jQuery v4 preview.
- Make a regex used in
angular.copyDoS-safe.- This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2023-26116).
- input:
- Make
URL_REGEXPless ambiguous.- This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2023-26118).
- Make
- jqLite:
- Add opt-in mode for compatibility with jQuery v4 via
angular.jqLite_jQueryLt4CompatibilityEnabled().- See Compatibility with jQuery v4 for more information.
- Add opt-in mode for compatibility with jQuery v4 via
1.9.0 (XLTS) - May 25, 2022
Security & Compatibility Fixes
- textarea:
- Avoid interpolating when going back/forward on IE.
- This fixes a medium-severity Cross-Site Scripting (XSS) vulnerability (CVE-2022-25869).
- Avoid interpolating when going back/forward on IE.
New Features
- Angular
- Implement
angular.version.vendor.- This now holds the value "XLTS.dev" for ease of determining if a supported version of AngularJS is running in a given app.
- Implement
Breaking Changes
textarea
- Avoid interpolating when going back/forward on IE:
Previously, the HTML contents of<textarea>elements were interpolated on all browsers. Due to how page caching works on Internet Explorer, this could lead to a<textarea>value's being interpolated when navigating back/forward to a page, even when the value was not originally inline in the HTML.
Due to security considerations, the HTML contents of<textarea>elements are no longer interpolated on Internet Explorer. If you want to set the<textarea>element's value by evaluating an AngularJS expression, you can use ng-bind or ng-prop-value.
For example:<!-- Before: --> <textarea>{{ 1 + 2 }}</textarea> <!-- After: --> <textarea ng-bind="1 + 2"></textarea> <!-- ...or... --> <textarea ng-prop-value="1 + 2"></textarea>
1.8.8 (XLTS) - April 11, 2022
Security & Compatibility Fixes
- $filter:
- Fix ReDoS issue in
currencyFilter.- This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2022-25844).
- Fix ReDoS issue in
- ngMocks:
- Use a more performant regex in
stripQueryAndHash.
- Use a more performant regex in
1.8.7 (XLTS) - September 21, 2021
Security & Compatibility Fixes
- jqLite:
- Print console warnings for vulnerable HTML input.
- This is related to a previous fix for a high-severity Cross Site Scripting (XSS) vulnerability (SNYK-JS-ANGULAR-572020).
- This is related to a previous fix for a medium-severity Cross Site Scripting (XSS) vulnerability (CVE-2020-7676).
- Print console warnings for vulnerable HTML input.
New Features
- ngCompileExtPreAssignBindings:
- Introduce the
ngCompileExtPreAssignBindingsmodule. Learn more in the Pre-assign Bindings guide. - Add types for the
ngCompileExtPreAssignBindingsmodule.
- Introduce the
1.8.6 (XLTS) - August 21, 2021
Notes
- This release also includes some documentation updates.
Security & Compatibility Fixes
- *:
- Fix the URLs for a number of console error messages.
- docs:
- Linting cleanup of the web worker used for search.
- $sce:
- Fix docs URL in
iequirkserror.
- Fix docs URL in
- $interpolate:
- Fix docs URL in
noconcaterror.
- Fix docs URL in
- jqlite:
noselerror points to an invalid URL.
- multiple:
- Update error references to use
code.angularjs.xlts.dev.
- Update error references to use
1.8.5 (XLTS) - May 29, 2021
Security & Compatibility Fixes
- Ix 68 npm security audit warnings, mostly with the build tooling.
- Fix 20 GitHub Dependabot security alerts.