Angular disclosed a server-side request forgery (SSRF) issue in @angular/platform-server that affects applications using Server-Side Rendering. The flaw, tracked as CVE-2026-41423, stems from improper handling of protocol-relative and backslash-based URLs passed from server engines such as Express into Angular rendering functions. A crafted request can cause Angular to treat an attacker-controlled domain as the application's origin, allowing relative HttpClient requests and PlatformLocation.hostname references to resolve to external infrastructure.
The issue can expose internal services, including private APIs and cloud metadata endpoints, and related advisory material also links the bug family to header injection risks in Angular SSR deployments. Angular fixed the vulnerability in versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, leaving earlier releases vulnerable where SSR is enabled and untrusted request paths can influence rendering context.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Angular fixed an SSRF flaw in @angular/platform-server caused by improper handling of protocol-relative and backslash URLs in SSR contexts. The issue was patched in versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8.
A GitHub security advisory was published for Angular SSR describing SSRF and header injection issues affecting Angular server-side rendering. The advisory is associated with angular/angular-cli.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.