Healthy and suitable to depend on. It has a long, active release history, strong organization backing, frequent commits from many contributors, and a documented release with tests and a changelog in the source repository. The package has no install scripts or deprecation notice.
96%
Total Score
100
100
100
100
50
| Title | Versions | Severity |
|---|---|---|
CVE-2026-88059 @angular/common is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 22.0.0 - 22.1.1, 21.0.0 - 21.2.20, 20.0.0 - 20.3.28 and 0.0.0 - 19.2.25. | 0.0.0 - 19.2.2520.0.0 - 20.3.2821.0.0 - 21.2.20 +1 more | Medium |
AIKIDO-2026-914160 @angular/common is vulnerable to Information Disclosure in versions 0.0.1 - 20.3.27, 21.0.0 - 21.2.19 and 22.0.0 - 22.1.0. | 0.0.1 - 20.3.2721.0.0 - 21.2.1922.0.0 - 22.1.0 | Medium |
AIKIDO-2026-872006 @angular/common is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 20.3.26, 21.0.0 - 21.2.18 and 22.0.0 - 22.0.1. | 0.0.1 - 20.3.2621.0.0 - 21.2.1822.0.0 - 22.0.1 | High |
AIKIDO-2026-977949 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @angular/common is vulnerable to Information Disclosure in versions 16.0.0 - 20.3.25, 21.0.0 - 21.2.17 and 22.0.0 - 22.0.2. | 16.0.0 - 20.3.2521.0.0 - 21.2.1722.0.0 - 22.0.2 | Medium |
CVE-2026-54268 @angular/common is vulnerable to Uncontrolled Resource Consumption in versions 22.0.0-next.0 - 22.0.1, 21.0.0-next.0 - 21.2.17, 20.0.0-next.0 - 20.3.25 and 0.0.0 - 19.2.25. | 0.0.0 - 19.2.2520.0.0-next.0 - 20.3.2521.0.0-next.0 - 21.2.17 +1 more | High |
| Dependency | Last Release | Score |
|---|---|---|
tslib Version ^2.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.