Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-27739

Опубликовано: 25 фев. 2026
Источник: nvd
EPSS Низкий

Описание

The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forgery (SSRF) vulnerability in the Angular SSR request handling pipeline. The vulnerability exists because Angular’s internal URL reconstruction logic directly trusts and consumes user-controlled HTTP headers specifically the Host and X-Forwarded-* family to determine the application's base origin without any validation of the destination domain. Specifically, the framework didn't have checks for the host domain, path and character sanitization, and port validation. This vulnerability manifests in two primary ways: implicit relative URL resolution and explicit manual construction. When successfully exploited, this vulnerability allows for arbitrary internal request steering. This can lead to credential exfiltration, internal network probing, and a confidentiality breach. In order to be vulnerable, the victim application mu

EPSS

Процентиль: 18%
0.00059
Низкий

Дефекты

CWE-918

Связанные уязвимости

debian
около 1 месяца назад

The Angular SSR is a server-rise rendering tool for Angular applicatio ...

github
около 1 месяца назад

Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

EPSS

Процентиль: 18%
0.00059
Низкий

Дефекты

CWE-918