GHSA-x288-3778-4hhx
CRITICALCVE-2026-27739A [Server-Side Request Forgery (SSRF)](https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/SSRF) vulnerability has been identified in the Angular SSR request handling pipeline. The vulnerability exists because Angular’s internal URL reconstruction logic directly trusts and consumes user-controlled HTTP headers specifically the Host and X-Forwarded- family to determine the application's b
- Affected
- >= 21.2.0-next.0, < 21.2.0-rc.0
- Fixed in
- 21.2.0-rc.1
- Weakness
- CWE-918
- Published
- 2026-02-25
- Source
- github