Visit AngularJS NES Home Page

AngularJS 1.8.x-1.9.x Release Notes

Comprehensive release notes and changelog for AngularJS 1.8.x-1.9.x, including security patches, bug fixes, and feature updates across all supported versions.

14 Patched Vulnerabilities
VEX Statements

AngularJS

1.9.12 (NES/XLTS) - June 17, 2026

Notes

  • Full package name(s) and version(s):
    • @neverendingsupport/angularjs@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-animate@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-aria@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-cookies@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-i18n@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-loader@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-message-format@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-messages@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-mocks@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-parse-ext@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-resource@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-route@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-sanitize@1.8.3-angularjs-1.9.12
    • @neverendingsupport/angularjs-touch@1.8.3-angularjs-1.9.12

Security & Compatibility Fixes

  • $sceDelegate:
    • Always apply resource URL matchers to entire URL.
      • This fixes a high-severity Cross-Site Scripting (XSS) vulnerability (CVE-2026-11998).

1.9.11 (NES/XLTS) - September 19, 2025

Notes

  • This release contains no functional changes from NES v1.9.10.
  • This release implements a new package naming scheme for the AngularJS packages. More information about the change can be found in the NES Decoupled Namespace Specification.
  • Full package name(s) and version(s):
    • @neverendingsupport/angularjs@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-animate@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-aria@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-cookies@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-i18n@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-loader@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-message-format@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-messages@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-mocks@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-parse-ext@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-resource@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-route@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-sanitize@1.8.3-angularjs-1.9.11
    • @neverendingsupport/angularjs-touch@1.8.3-angularjs-1.9.11

1.9.10 (NES/XLTS) - May 28, 2025

Notes

Security & Compatibility Fixes

  • $compile:
    • Improve performance of srcset attribute sanitization.
    • Improve performance of comment-based directive collection.
  • $injector:
    • Improve performance of implicit dependency annotation.
  • linky:
    • Prevent ReDoS when searching for URLs in text.
      • This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2025-4690).
  • ngMocks:
    • Improve performance of trailing slash removal in $httpBackend.

1.9.9 (NES/XLTS) - March 19, 2025

Security & Compatibility Fixes

  • $sanitize:
    • Sanitize image sources on <image> SVG elements.
      • This fixes a medium-severity Content Spoofing vulnerability (CVE-2025-2336).

1.9.8 (NES/XLTS) - February 18, 2025

Security & Compatibility Fixes

  • $compile:
    • Always sanitize image sources on <image> SVG element.
      • This fixes a medium-severity Content Spoofing vulnerability (CVE-2025-0716).

Breaking Changes

$compile
  • Always sanitize image sources on <image> SVG element:
    In the unlikely case that an app relied on trusted $sce.RESOURCE_URL values, via $sceDelegateProvider.trustedResourceUrlList()/$sceDelegateProvider.resourceUrlWhitelist() or $sce.trustAs($sce.RESOURCE_URL, ...) or $sce.trustAsResourceUrl(), for the purpose of binding to the xlink:href property of <image> SVG elements and if the values do not pass the regular image URL sanitization, the affected SVG images will not be rendered.
    To fix this, you need to ensure that the values used for binding to the xlink:href attributes of <image> SVG elements are considered safe image URLs, via $compileProvider.imgSrcSanitizationTrustedUrlList().
    Before:
    angular
        .module('myApp')
        .config(['$sceDelegateProvider', $sceDelegateProvider => {
          $sceDelegateProvider.trustedResourceUrlList([
            // ...other resource URLs...
    
            // Allow resource URLs from `https://my.domain.com/images/`
            // for the purpose of using with `image[xlink:href]`.
            /https:\/\/my\.domain\.com\/images\/.*/,
          ]);
        }]);
    // ...or...
    angular
        .module('myApp')
        .run(['$rootScope', '$sce', ($rootScope, $sce) => {
          // Trust a specific URL as a resource URL for the purpose
          // of using in templates with `image[xlink:href]`.
          $rootScope.trustedImageUrl = $sce.trustAsResourceUrl(
              'https://my.domain.com/images/some-image.png');
        }]);
    

    After:
    angular
        .module('myApp')
        .config([
          '$compileProvider', '$sceDelegateProvider',
          ($compileProvider, $sceDelegateProvider) => {
            $sceDelegateProvider.trustedResourceUrlList([
              // ...other resource URLs...
            ]);
    
            $compileProvider.imgSrcSanitizationTrustedUrlList(
              // Allow image URLs from `https://my.domain.com/images/`
              // for the purpose of using with `<img>` or `<image>`.
              /^https:\/\/my\.domain\.com\/images\//,
    
              // ...or...
    
              // Trust specific URLs as image URLs for the purpose
              // of using in templates with `<img>` or `<image>`.
              /^https:\/\/my\.domain\.com\/images\/(?:some-image\.png|other-image\.jpg)$/,
            );
          },
        ]);
    

1.9.7 (NES/XLTS) - July 18, 2024

Notes

  • This release contains some metadata fixes and improvements:
    • Preserve license file headers in minified files.
    • Use correct names and versions in bower.json files.

Security & Compatibility Fixes

  • jqLite:
    • Add opt-in mode for compatibility with jQuery v4 via angular.jqLite_jQueryLt4CompatibilityEnabled().

1.9.6 (NES/XLTS) - May 21, 2024

Security & Compatibility Fixes

  • $compile:
    • Always sanitize image sources on <source> element.
      • This fixes a medium-severity Content Spoofing vulnerability (CVE-2024-8373).
  • srcset:
    • Prevent bypassing image source sanitization with (ng(Attr))Srcset.
      • This fixes a medium-severity Content Spoofing vulnerability (CVE-2024-8372).

1.9.5 (NES) - February 4, 2024

Notes

  • This release contains no functional changes from NES v1.9.4.
  • This release contains only metadata fixes and improvements: Fixed deployment script that resulted in v1.9.4 incorrectly registering as v1.9.5-local+sha.6756ba9 in various places (code headers, angular global object, etc.).

1.9.4 (NES) - October 22, 2023

Notes

  • Repackaging XLTS for AngularJS as AngularJS NES
    • XLTS merged with HeroDevs in September 2023 and continues to support AngularJS under Never-Ending Support (NES).
  • AngularJS NES v1.5.21 is functionally equivalent to XLTS for AngularJS v1.5.19.

1.9.3 (XLTS) - August 18, 2023

Security & Compatibility Fixes

  • $compile:
    • Fix a possible ReDoS in ng-srcset parsing.
      • This fixes a high-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2024-21490).
  • route:
    • Suppress warning from CodeQL regarding escaping backslash characters.

1.9.2 (XLTS) - July 12, 2023

Security & Compatibility Fixes

  • ngAnimate:
  • browserTrigger:
    • Fix focus triggering in IE with jQuery >=3.7.0.
  • bootstrap:
    • No longer trigger RegExp warning in CodeQL scans.

1.9.1 (XLTS) - April 4, 2023

Security & Compatibility Fixes

  • $compile:
    • Fix mergeConsecutiveTextNodes logic for jQuery v4 preview.
  • $resource:
    • Avoid DoS in stripping trailing slashes.
      • This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2023-26117).
  • Angular:
    • Collect jQuery nodes between two elements correctly for jQuery v4 preview.
    • Make a regex used in angular.copy DoS-safe.
      • This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2023-26116).
  • input:
    • Make URL_REGEXP less ambiguous.
      • This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2023-26118).
  • jqLite:
    • Add opt-in mode for compatibility with jQuery v4 via angular.jqLite_jQueryLt4CompatibilityEnabled().

1.9.0 (XLTS) - May 25, 2022

Security & Compatibility Fixes

  • textarea:
    • Avoid interpolating when going back/forward on IE.
      • This fixes a medium-severity Cross-Site Scripting (XSS) vulnerability (CVE-2022-25869).

New Features

  • Angular
    • Implement angular.version.vendor.
      • This now holds the value "XLTS.dev" for ease of determining if a supported version of AngularJS is running in a given app.

Breaking Changes

textarea
  • Avoid interpolating when going back/forward on IE:
    Previously, the HTML contents of <textarea> elements were interpolated on all browsers. Due to how page caching works on Internet Explorer, this could lead to a <textarea> value's being interpolated when navigating back/forward to a page, even when the value was not originally inline in the HTML.
    Due to security considerations, the HTML contents of <textarea> elements are no longer interpolated on Internet Explorer. If you want to set the <textarea> element's value by evaluating an AngularJS expression, you can use ng-bind or ng-prop-value.
    For example:
    <!-- Before: -->
    <textarea>{{ 1 + 2 }}</textarea>
    
    <!-- After: -->
    <textarea ng-bind="1 + 2"></textarea>
    <!-- ...or... -->
    <textarea ng-prop-value="1 + 2"></textarea>
    

1.8.8 (XLTS) - April 11, 2022

Security & Compatibility Fixes

  • $filter:
    • Fix ReDoS issue in currencyFilter.
      • This fixes a medium-severity Regular expression Denial of Service (ReDoS) vulnerability (CVE-2022-25844).
  • ngMocks:
    • Use a more performant regex in stripQueryAndHash.

1.8.7 (XLTS) - September 21, 2021

Security & Compatibility Fixes

  • jqLite:
    • Print console warnings for vulnerable HTML input.
      • This is related to a previous fix for a high-severity Cross Site Scripting (XSS) vulnerability (SNYK-JS-ANGULAR-572020).
      • This is related to a previous fix for a medium-severity Cross Site Scripting (XSS) vulnerability (CVE-2020-7676).

New Features

  • ngCompileExtPreAssignBindings:
    • Introduce the ngCompileExtPreAssignBindings module. Learn more in the Pre-assign Bindings guide.
    • Add types for the ngCompileExtPreAssignBindings module.

1.8.6 (XLTS) - August 21, 2021

Notes

  • This release also includes some documentation updates.

Security & Compatibility Fixes

  • *:
    • Fix the URLs for a number of console error messages.
  • docs:
    • Linting cleanup of the web worker used for search.
  • $sce:
    • Fix docs URL in iequirks error.
  • $interpolate:
    • Fix docs URL in noconcat error.
  • jqlite:
    • nosel error points to an invalid URL.
  • multiple:
    • Update error references to use code.angularjs.xlts.dev.

1.8.5 (XLTS) - May 29, 2021

Security & Compatibility Fixes

  • Ix 68 npm security audit warnings, mostly with the build tooling.
  • Fix 20 GitHub Dependabot security alerts.