CoreUI PRO for Angular v5.6.21 - Angular 21.2.5 Security Update
We are pleased to announce the release of CoreUI PRO for Angular v5.6.21. This critical security update brings full support for Angular 21.2.5 and includes important security patches addressing multiple vulnerabilities in flatted, socket.io-parser, and undici packages. This update ensures your enterprise Angular applications run securely with the latest framework improvements and comprehensive dependency updates.
Speed up your responsive apps and websites with fully-featured, ready-to-use open-source admin panel templates—free to use and built for efficiency.
How to Update
To update to CoreUI PRO v5.6.21 for Angular 21.2.5, follow these simple steps:
ng update @angular/[email protected] @angular/[email protected] @coreui/coreui-pro@~5.24.0 @coreui/angular-pro@~5.6.21
What’s New
Angular 21.2.5 Support
CoreUI PRO for Angular v5.6.21 fully supports Angular 21.2.5, delivering:
- Security Fixes: Critical security patches from the Angular team
- Stability Updates: Framework-level bug fixes and improvements
- Performance: Runtime optimizations and enhancements
- Compatibility: Enhanced compatibility with Angular ecosystem
- PRO Components: All exclusive PRO components updated and secured
Critical Security Patches
This release addresses three important security vulnerabilities to ensure your enterprise applications are protected:
1. Flatted Library Vulnerability (GHSA-rf6f-7fwh-wjgh)
Patched a critical security issue in the flatted serialization library. This vulnerability could potentially be exploited in applications that use flatted for data serialization.
2. Socket.io-parser Vulnerability (GHSA-677m-j7p3-52f9)
Resolved a security advisory in socket.io-parser that could affect applications using Socket.io for real-time communication.
3. Undici Package - Multiple Security Issues
Updated undici to version ^7.24.2 to address six critical security vulnerabilities:
- WebSocket Parsing Vulnerabilities: Fixed parsing issues that could lead to security exploits
- HTTP Smuggling Concerns: Addressed potential HTTP request smuggling attacks
- Memory Consumption Weaknesses: Resolved memory exhaustion vulnerabilities
- WebSocket Validation Gaps: Enhanced WebSocket connection validation
- CRLF Injection Risks: Mitigated CRLF injection attack vectors
We strongly recommend updating enterprise applications immediately to ensure protection against these known vulnerabilities and maintain compliance with security best practices.
Development Tooling Updates
Updated Angular and development tools to the latest versions for enhanced development experience:
- Angular Core and CLI: Full support for Angular 21.2.5
- Build Tools: Updated @angular-devkit/schematics, @angular/build, and @angular/cli
- Component Development Kit: Latest @angular/cdk
- Code Quality: Updated angular-eslint and typescript-eslint packages
- Package Management: Updated ng-packagr for better library builds
- Better Developer Experience: Faster builds and improved error reporting
PRO Components
All exclusive enterprise components updated to v5.6.21:
- Calendar - Advanced scheduling component
- Date & Time Pickers - Professional date selection
- Multi Select - Enhanced multi-selection
- Smart Table - Enterprise data table
- Smart Pagination - Intelligent pagination
- Loading Button - Interactive loading states
- And more PRO-exclusive components
Dependency Updates
We have updated key dependencies to their latest versions, ensuring improved performance, security, and compatibility with Angular 21.2.5:
Angular Core Updates
@angular/animationsfrom:21.2.3to:21.2.5@angular/commonfrom:21.2.3to:21.2.5@angular/compilerfrom:21.2.3to:21.2.5@angular/corefrom:21.2.3to:21.2.5@angular/formsfrom:21.2.3to:21.2.5@angular/localizefrom:21.2.3to:21.2.5@angular/platform-browserfrom:21.2.3to:21.2.5@angular/platform-browser-dynamicfrom:21.2.3to:21.2.5@angular/routerfrom:21.2.3to:21.2.5
Angular Development Tools
@angular-devkit/schematicsfrom:21.2.2to:21.2.3@angular/buildfrom:21.2.2to:21.2.3@angular/clifrom:21.2.2to:21.2.3@angular/compiler-clifrom:21.2.3to:21.2.5@angular/language-servicefrom:21.2.3to:21.2.5@angular/cdkfrom:21.2.2to:21.2.3
Build and Package Management Tools
ng-packagrfrom:21.2.2to:21.2.3@angular-eslint/builderfrom:19.0.1to:19.0.2@angular-eslint/eslint-pluginfrom:19.0.1to:19.0.2@angular-eslint/eslint-plugin-templatefrom:19.0.1to:19.0.2@angular-eslint/schematicsfrom:19.0.1to:19.0.2@angular-eslint/template-parserfrom:19.0.1to:19.0.2
Code Quality and Linting
eslintfrom:9.19.0to:9.20.0typescript-eslintfrom:8.57.0to:8.58.0
Security Overrides
undici- overridden to:^7.24.2(addresses six critical vulnerabilities)
These updates bring your enterprise application to the latest Angular 21.2.5 and related library versions with critical security improvements.
Released Packages
This release includes the updated CoreUI PRO Angular package:
- @coreui/angular-pro: v5.6.21 - PRO Angular components with exclusive enterprise features
Migration Notes
This is a security and maintenance release with full backward compatibility. No breaking changes to PRO components were introduced. If you’re upgrading:
- Update dependencies using the
ng updatecommand above - Review your application for any console warnings
- Run your test suite to ensure everything works as expected
- Verify security patches by running
npm auditto check for vulnerabilities - Test all PRO components in your application
- Verify WebSocket and real-time features if applicable
Why Update?
Updating to CoreUI PRO for Angular v5.6.21 provides critical benefits:
- Security: Critical patches for three major vulnerabilities (flatted, socket.io-parser, undici)
- Latest Angular: Access to Angular 21.2.5 improvements and security fixes
- PRO Components: Updated and secured enterprise-grade components
- Stability: Framework-level bug fixes and enhancements
- Best Practices: Stay current with latest security standards
- Enterprise Support: Professionally maintained PRO components
- Compliance: Meet security compliance requirements with latest patches
Security Recommendations
After updating:
- Verify Patches: Ensure all vulnerabilities are resolved by running
npm audit - Test Thoroughly: Verify all functionality, especially WebSocket and real-time features
- Audit Dependencies: Check for any additional security advisories
- Update Regularly: Keep your dependencies up to date with regular maintenance
- Monitor Advisories: Subscribe to security advisories for Angular and CoreUI
- Document Update: Record security updates for compliance and audit purposes
- Test PRO Components: Verify all PRO components functionality after update
Additional Resources
- Security Advisory GHSA-rf6f-7fwh-wjgh (flatted)
- Security Advisory GHSA-677m-j7p3-52f9 (socket.io-parser)
- Angular Documentation
- CoreUI PRO for Angular Documentation
For full details, see the changelog on GitHub.



