logo

Angular SSR Request Vulnerability Allows Attackers to Trick Applications into Sending Unauthorized Requests

ID: a58c31bb-fb05-5c05-8749-054cd146d6a3

STIX ID: report--a58c31bb-fb05-5c05-8749-054cd146d6a3

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical SSRF vulnerability (CVE-2026-27739) in Angular Server-Side Rendering allows untrusted Host and X-Forwarded-* headers to manipulate the application base URL and construct unsafe requests, enabling attackers to redirect requests to malicious servers, exfiltrate authorization headers or cookies, and probe internal services. The advisory details attack scenarios, impact, recommended patched Angular versions (21.2.0-rc.1, 21.1.5, 20.3.17, 19.2.21) and mitigation steps such as avoiding req.headers for URL construction and enforcing strict header validation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.