CVE-2026-27738Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the 21.x branch prior to 21.1.5 and 21.2.0-rc.1. The logic normalizes URL segments by stripping leading slashes; however, it only removes a single leading slash. When an Angular SSR application is deployed behind a proxy that passes the `X-Forwarded-Prefix` header, an attacker can provide a value starting with three slashes. This vulnerability allows attackers to conduct large-scale phishing and SEO hijacking. In order to be vulnerable, the application must use Angular SSR, the application must have routes that perform internal redirects, the infrastructure (Reverse Proxy/CDN) must pass the `X-Forwarded-Prefix` header to the SSR process without sanitization, and the cache must not vary on the `X-Forwarded-Prefix` header. Versions 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 contain a patch. Until the patch is applied, developers should sanitize the `X-Forwarded-Prefix` header in their`server.ts` before the Angular engine processes the request.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-26)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-25: 1Mentions · 2026-02-26: 3Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 302-2502-26
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-263
Disclosure3
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27738 The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on th… https://www.cve.org/CVERecord?id=CVE-2026-27738 ----- Traducción: CVE-2026-27738 El … http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27738, an Open Redirect flaw in Angular SSR’s URL processing logic, without mentioning PoC, exploit, or patch details.

    0000043
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27738 The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on th… https://www.cve.org/CVERecord?id=CVE-2026-27738

    Post summary

    The text announces an open redirect vulnerability in Angular SSR (CVE-2026-27738) but provides no PoC, exploit, or patch information.

    00000178
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27738: Angular SSR: The One-Slash Wonder (CVE-2026-27738) A deceptively simple logic error in Angular's Server-Side Rendering (SSR) engine allows attackers to turn internal redirects into open redirects. By exploiting how the framework normal... https://cvereports.com/reports/CVE-2026-27738

    Post summary

    The report highlights a logic flaw in Angular's SSR that converts internal redirects into open redirects, but it does not provide a PoC, exploit code, or patch information.

    0000038
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27738 Open Redirect Vulnerability in Angular SSR Across Multiple Versions https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27738

    Post summary

    A new open redirect vulnerability (CVE-2026-27738) affecting Angular SSR across multiple versions has been disclosed, with no PoC, exploit, patch, or active exploitation details provided.

    0000043
    4.0K followersView on X

Explore more