logo

High-Severity SSRF Flaw Uncovered in Angular’s Server-Side Rendering

ID: f03ff84d-118c-54a8-9008-cab9ecf207db

STIX ID: report--f03ff84d-118c-54a8-9008-cab9ecf207db

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity SSRF vulnerability (CVSS 8.7) in the @angular/platform-server package allows attackers to hijack the application’s internal origin during server-side rendering by exploiting URL normalization (e.g., backslashes or protocol-relative URLs), which can redirect relative HTTP requests to attacker-controlled domains; affected APIs include renderModule, renderApplication, and the Common Engine. The Angular team has released patches across multiple version lines and provides a middleware-based URL-sanitization workaround for teams that cannot immediately upgrade.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.