Steering the Server: Critical 9.2 Severity SSRF Flaw in Angular SSR Allows Internal Network Probing
ID: 2442a4c3-4309-50a1-bab3-0f30651dc5ad
STIX ID: report--2442a4c3-4309-50a1-bab3-0f30651dc5ad
Feed Name: securityonline.info
A critical SSRF vulnerability (CVE-2026-27739, CVSS 9.2) was disclosed in Angular’s Server‑Side Rendering request handling: unvalidated Host and X-Forwarded-* headers can be manipulated to change the base origin used by HttpClient, enabling attackers to redirect internal requests to malicious or internal endpoints (leading to credential theft, metadata access such as 169.254.169.254, and data exfiltration). The report lists patched versions (21.2.0-rc.1, 21.1.5, 20.3.17, 19.2.21) and recommends using absolute/trusted URLs or strict header validation middleware as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
