logo

Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing

ID: 2442a4c3-4309-50a1-bab3-0f30651dc5ad

STIX ID: report--2442a4c3-4309-50a1-bab3-0f30651dc5ad

Feed Name: securityonline.info

Threat Score
82/100

Date Published: 2026-03-02

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical SSRF vulnerability (CVE-2026-27739, CVSS 9.2) was disclosed in Angular’s Server‑Side Rendering request handling: unvalidated Host and X-Forwarded-* headers can be manipulated to change the base origin used by HttpClient, enabling attackers to redirect internal requests to malicious or internal endpoints (leading to credential theft, metadata access such as 169.254.169.254, and data exfiltration). The report lists patched versions (21.2.0-rc.1, 21.1.5, 20.3.17, 19.2.21) and recommends using absolute/trusted URLs or strict header validation middleware as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.