Angular SSR Flaw Enables Unauthorized Server-Side Requests in Web Apps
ID: 2917dfc4-4381-563f-870e-4738e71ad021
STIX ID: report--2917dfc4-4381-563f-870e-4738e71ad021
Feed Name: GBHackers
An urgent advisory for CVE-2026-27739: a critical (CVSS v4 10.0) SSRF and header-injection vulnerability in @angular/ssr, @nguniversal/common, and @nguniversal/express-engine caused by trusting unvalidated Host and X-Forwarded-* headers; attackers can redirect server-side requests to arbitrary destinations (including cloud metadata endpoints) to exfiltrate credentials or probe internal services. Patched versions are listed and mitigations include upgrading to the patched releases, using absolute URLs, and implementing strict header validation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
