Package compatibility

Angular 18.0

What Node.js versions does this Angular version support?

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Declared Node.js requirement

engines.node
^18.13.0 || >=20.9.0
Tip version
18.0.1
Source
npm Registry (engines.node)

Node.js compatibility matrix

Evaluated against CompatHub Node.js VersionLines. Compatibility and lifecycle status are separate signals.

Other Angular lines

Security

Advisories affecting Angular 18.0 (OSV.dev evidence). Known exploited status, due dates, and ransomware use from CISA KEV when matched.

Known vulnerabilities
6
Known exploited
0
Highest CVSS
  • CVE-2026-69151GHSA-jj27-h5hq-8x99

    Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes

    Affected:
    <=19.2.25
    Source:
    OSV source
  • CVE-2026-50557GHSA-f3m7-gqxr-g87x

    Angular: Template and Attribute Namespace Sanitization Bypass (XSS)

    Affected:
    <=18.2.14
    Source:
    OSV source · Advisory
  • CVE-2026-52725GHSA-692r-grfm-v8x7

    @angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)

    Affected:
    <=18.2.14
    Source:
    OSV source · Advisory
  • CVE-2026-54267GHSA-rgjc-h3x7-9mwg

    Angular Client Hydration DOM Clobbering & Response-Cache Poisoning

    Affected:
    <=19.2.25
    Source:
    OSV source · Advisory
  • CVE-2026-27970GHSA-prjf-86w9-mfqv

    Angular i18n vulnerable to Cross-Site Scripting

    Affected:
    <=18.2.14
    Source:
    OSV source · Advisory
  • CVE-2026-22610GHSA-jrmj-c5cx-3cw6

    Angular has XSS Vulnerability via Unsanitized SVG Script Attributes

    Affected:
    <=18.2.14
    Source:
    OSV source · Advisory