Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46417

Опубликовано: 22 июн. 2026
Источник: redhat
EPSS Низкий

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server. The issue stems from how the server-side rendering (SSR) engine processes the request URL provided to the rendering entry points. When an absolute-form URL (e.g., http://evil.com) is passed to the rendering engine, the internal ServerPlatformLocation can be manipulated into adopting the attacker-controlled domain as the "current" hostname. Consequently, any relative HttpClient requests or PlatformLocation.hostname references are redirected to the attacker controlled server, potentially exposing internal APIs or metadata services. This vulnerability is fixed in 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22.

Отчет

This Important Server-Side Request Forgery (SSRF) vulnerability in @angular/platform-server within Red Hat JBoss Fuse allows an attacker to redirect internal HttpClient requests or PlatformLocation.hostname references to an arbitrary external server. This occurs when an absolute-form URL is provided to the server-side rendering engine, potentially exposing internal APIs or metadata services. Red Hat Enterprise Linux is not affected as the vulnerable code is not in its execution path.

Меры по смягчению последствий

To mitigate this vulnerability, implement strict URL validation within the server entry point of applications utilizing @angular/platform-server. Developers should ensure that the req.url is validated against a predefined list of trusted hostnames or normalized to a relative path before being passed to renderApplication or renderModule. This prevents the server-side rendering engine from being manipulated by attacker-controlled domains.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8dotnet5.0-build-reference-packagesNot affected
Red Hat Fuse 7platform-serverOut of support scope

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2491444@angular/platform-server: Angular: SSRF via Hostname Hijacking in @angular/platform-server

EPSS

Процентиль: 13%
0.00221
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 2 месяцев назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server. The issue stems from how the server-side rendering (SSR) engine processes the request URL provided to the rendering entry points. When an absolute-form URL (e.g., http://evil.com) is passed to the rendering engine, the internal ServerPlatformLocation can be manipulated into adopting the attacker-controlled domain as the "current" hostname. Consequently, any relative HttpClient requests or PlatformLocation.hostname references are redirected to the attacker controlled server, potentially exposing internal APIs or metadata services. This vulnerability is fixed in 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22.

CVSS3: 6.1
nvd
около 2 месяцев назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server. The issue stems from how the server-side rendering (SSR) engine processes the request URL provided to the rendering entry points. When an absolute-form URL (e.g., http://evil.com) is passed to the rendering engine, the internal ServerPlatformLocation can be manipulated into adopting the attacker-controlled domain as the "current" hostname. Consequently, any relative HttpClient requests or PlatformLocation.hostname references are redirected to the attacker controlled server, potentially exposing internal APIs or metadata services. This vulnerability is fixed in 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22.

CVSS3: 6.1
debian
около 2 месяцев назад

Angular is a development platform for building mobile and desktop web ...

CVSS3: 6.1
github
3 месяца назад

@angular/platform-server: SSRF via Hostname Hijacking

EPSS

Процентиль: 13%
0.00221
Низкий