Impact
Angular Server‑Side Rendering was able to process user‑controlled URLs via HttpClient after validating them with WHATWG URL parsing. During URL resolution, a trim operation removed leading Unicode whitespace after a same‑origin check, turning a relative path into a protocol‑relative attacker‑controlled URL. If the application attached sensitive server‑side credentials such as Authorization headers to accepted requests, the dispatcher sent the request to the attacker‑controlled origin, exposing credentials and allowing server‑side requests to arbitrary destinations.
Affected Systems
All Angular applications that use @angular/platform-server before version 20.3.30, 21.2.22, or 22.1.4 are vulnerable. This includes any application built with Angular that performs URL resolution for server‑side rendering and may forward request headers.
Risk and Exploitability
The CVSS score of 8.6 classifies this flaw as high severity. EPSS data is not available, but the vulnerability is exploitable without special conditions; the attacker merely needs to influence a user‑controlled URL. The attack path involves manipulating the URL string, causing the application to resolve and send a request to an external host while sending internal credentials, leading to potential data exfiltration or remote command execution on the target server.
OpenCVE Enrichment
Github GHSA