๐Ÿ” CVE Alert

CVE-2026-27738

UNKNOWN 0.0

Angular SSR has an Open Redirect via X-Forwarded-Prefix

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the 21.x branch prior to 21.1.5 and 21.2.0-rc.1. The logic normalizes URL segments by stripping leading slashes; however, it only removes a single leading slash. When an Angular SSR application is deployed behind a proxy that passes the `X-Forwarded-Prefix` header, an attacker can provide a value starting with three slashes. This vulnerability allows attackers to conduct large-scale phishing and SEO hijacking. In order to be vulnerable, the application must use Angular SSR, the application must have routes that perform internal redirects, the infrastructure (Reverse Proxy/CDN) must pass the `X-Forwarded-Prefix` header to the SSR process without sanitization, and the cache must not vary on the `X-Forwarded-Prefix` header. Versions 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 contain a patch. Until the patch is applied, developers should sanitize the `X-Forwarded-Prefix` header in their`server.ts` before the Angular engine processes the request.

CWE CWE-601
Vendor angular
Product angular-cli
Published Feb 25, 2026
Last Updated Feb 27, 2026
Stay Ahead of the Next One

Get instant alerts for angular angular-cli

Be the first to know when new unknown vulnerabilities affecting angular angular-cli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

angular / angular-cli
>= 21.2.0-next.2, < 21.2.0-rc.0 >= 21.0.0-next.0, < 21.1.5 >= 20.0.0-next.0, < 20.3.17 >= 19.0.0-next.0, < 19.2.21

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/angular/angular-cli/security/advisories/GHSA-xh43-g2fq-wjrj github.com: https://github.com/angular/angular-cli/issues/32501 github.com: https://github.com/angular/angular-cli/pull/32521 github.com: https://github.com/angular/angular-cli/commit/877f017ace4b83277d773aa37f5813e5e9faec7e