Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes user-controlled resource or request URLs through HttpClient after application code validates them with WHATWG URL parsing. The resolveUrl and parseUrl utilities called String.prototype.trim(), which removed leading Unicode whitespace such as U+00A0 or U+FEFF after the input passed a same-origin check, converting a relative path into a protocol-relative attacker-controlled URL. In affected applications that attach sensitive server-side credentials such as Authorization headers to approved requests, relativeUrlsTransformerInterceptorFn then dispatched the request to the attacker-controlled origin, causing SSRF and credential disclosure. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
Published: 2026-09-10
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Server Side Request Forgery with credential disclosure
Action: Immediate Patch
AI Analysis

Impact

Angular Server‑Side Rendering was able to process user‑controlled URLs via HttpClient after validating them with WHATWG URL parsing. During URL resolution, a trim operation removed leading Unicode whitespace after a same‑origin check, turning a relative path into a protocol‑relative attacker‑controlled URL. If the application attached sensitive server‑side credentials such as Authorization headers to accepted requests, the dispatcher sent the request to the attacker‑controlled origin, exposing credentials and allowing server‑side requests to arbitrary destinations.

Affected Systems

All Angular applications that use @angular/platform-server before version 20.3.30, 21.2.22, or 22.1.4 are vulnerable. This includes any application built with Angular that performs URL resolution for server‑side rendering and may forward request headers.

Risk and Exploitability

The CVSS score of 8.6 classifies this flaw as high severity. EPSS data is not available, but the vulnerability is exploitable without special conditions; the attacker merely needs to influence a user‑controlled URL. The attack path involves manipulating the URL string, causing the application to resolve and send a request to an external host while sending internal credentials, leading to potential data exfiltration or remote command execution on the target server.

Generated by OpenCVE AI on September 10, 2026 at 22:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Angular to the fixed versions (20.3.30, 21.2.22, or 22.1.4 or later).
  • If an upgrade is not immediately possible, remove or prevent Transmission oftrusted URLs in SSR.
  • As a temporary measure, restrict outbound traffic from the Angular server so that SSRF requests cannot reach external networks.

Generated by OpenCVE AI on September 10, 2026 at 22:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f6mr-pjwc-34m4 Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
History

Tue, 29 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Angular
Angular angular
Vendors & Products Angular
Angular angular

Thu, 10 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes user-controlled resource or request URLs through HttpClient after application code validates them with WHATWG URL parsing. The resolveUrl and parseUrl utilities called String.prototype.trim(), which removed leading Unicode whitespace such as U+00A0 or U+FEFF after the input passed a same-origin check, converting a relative path into a protocol-relative attacker-controlled URL. In affected applications that attach sensitive server-side credentials such as Authorization headers to approved requests, relativeUrlsTransformerInterceptorFn then dispatched the request to the attacker-controlled origin, causing SSRF and credential disclosure. This issue is fixed in versions 20.3.30, 21.2.22, and 22.1.4.
Title Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:56:52.167Z

Reserved: 2026-09-09T21:22:45.434Z

Link: CVE-2026-88056

cve-icon Vulnrichment

Updated: 2026-09-15T14:56:47.816Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T19:17:41.477

Modified: 2026-09-29T19:02:56.377

Link: CVE-2026-88056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:45:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)