9.1

CVE-2026-88056

Exploit

Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes user-controlled resource or request URLs through HttpClient after application code validates them with WHATWG URL parsing. The resolveUrl and parseUrl utilities called String.prototype.trim(), which removed leading Unicode whitespace such as U+00A0 or U+FEFF after the input passed a same-origin check, converting a relative path into a protocol-relative attacker-controlled URL. In affected applications that attach sensitive server-side credentials such as Authorization headers to approved requests, relativeUrlsTransformerInterceptorFn then dispatched the request to the attacker-controlled origin, causing SSRF and credential disclosure. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Angular ≫ Angular SwPlatform node.js Version >= 19.0.0 <= 19.2.25
Angular ≫ Angular SwPlatform node.js Version >= 20.0.0 < 20.3.30
Angular ≫ Angular SwPlatform node.js Version >= 21.0.0 < 21.2.22
Angular ≫ Angular SwPlatform node.js Version >= 22.0.0 < 22.1.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.359
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
security-advisories@github.com 8.6 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://github.com/angular/angular/security/advisories/GHSA-f6mr-pjwc-34m4
Vendor Advisory
Exploit
Mitigation
https://github.com/angular/angular/commit/3e924cc8dbbb57f23b262cb8f0d7e2bd0673034c
Patch
https://github.com/angular/angular/commit/5aa6d97deb9ef1de14e23748b7fa74f97d183132
Patch
https://github.com/angular/angular/commit/71e52d1396b9cef98652929b73e08c4cde645970
Patch
https://github.com/angular/angular/releases/tag/v20.3.30
Release Notes
https://github.com/angular/angular/releases/tag/v21.2.22
Release Notes
https://github.com/angular/angular/releases/tag/v22.1.4
Release Notes