← Back

CVE-2026-50168

nvd nist
Published: Jun 22, 2026Modified: Jul 9, 2026

JSON object

Loading...
8.8
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security-advisories@github.com (Secondary)

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allows remote attackers to bypass host allowlist constraints and direct server-side outgoing requests to arbitrary external endpoints. This occurs due to a parser differential between the strict WHATWG URL parser used for allowlist validation and the lenient Domino URL parser used to initialize the server emulated DOM. When a server-side request contains a malformed URL with a double port structure (e.g., http://evil.com:80:80/path), Node's strict URL.canParse(url) logic returns false and skips host check validation entirely. However, the same malformed URL is later accepted and parsed leniently by Domino's internal parser, which resolves the origin to http://evil.com:80. The Angular SSR HTTP request interceptor (relativeUrlsTransformerInterceptorFn) then resolves all relative backend HTTP requests against this adopted origin, executing the SSRF attack. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

Affected (19)

Products: Angular: Angular
1 product
Angular
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Angular
From 19.0.0 to 19.2.23
From 2.0.0 to 18.2.14
From 20.0.0 to 20.3.22
From 21.0.0 to 21.2.15
Version 22.0.0 next0
Version 22.0.0 next10
Version 22.0.0 next11
Version 22.0.0 next12
Version 22.0.0 next1
Version 22.0.0 next2
Version 22.0.0 next3
Version 22.0.0 next4
Version 22.0.0 next5
Version 22.0.0 next6
Version 22.0.0 next7
Version 22.0.0 next8
Version 22.0.0 next9
Version 22.0.0 rc0
Version 22.0.0 rc1

References (2)

Source: security-advisories@github.com
Issue TrackingPatch
Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.