CVE-2026-27739Disclosure

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forgery (SSRF) vulnerability in the Angular SSR request handling pipeline. The vulnerability exists because Angular’s internal URL reconstruction logic directly trusts and consumes user-controlled HTTP headers specifically the Host and `X-Forwarded-*` family to determine the application's base origin without any validation of the destination domain. Specifically, the framework didn't have checks for the host domain, path and character sanitization, and port validation. This vulnerability manifests in two primary ways: implicit relative URL resolution and explicit manual construction. When successfully exploited, this vulnerability allows for arbitrary internal request steering. This can lead to credential exfiltration, internal network probing, and a confidentiality breach. In order to be vulnerable, the victim application must use Angular SSR (Server-Side Rendering), the application must perform `HttpClient` requests using relative URLs OR manually construct URLs using the unvalidated `Host` / `X-Forwarded-*` headers using the `REQUEST` object, the application server must be reachable by an attacker who can influence these headers without strict validation from a front-facing proxy, and the infrastructure (Cloud, CDN, or Load Balancer) must not sanitize or validate incoming headers. Versions 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 contain a patch. Some workarounds are available. Avoid using `req.headers` for URL construction. Instead, use trusted variables for base API paths. Those who cannot upgrade immediately should implement a middleware in their `server.ts` to enforce numeric ports and validated hostnames.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 17 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 15 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 5 mentions (2026-03-02); latest day: 1
  • 17 total mentions across 8 days

Deep dive

Activity timeline17 mentions / 8d
01345Mentions · 2026-02-25: 1Mentions · 2026-02-26: 4Mentions · 2026-02-27: 2Mentions · 2026-03-02: 5Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-09: 2Mentions · 2026-09-16: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-02: 4Patch / Workaround · 2026-03-05: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 4Technical Details · 2026-02-27: 1Technical Details · 2026-03-02: 5Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 202-2502-2602-2703-0203-0503-0603-0909-16
Signal classification3 categories
Disclosure
952.9%
Patch
635.3%
General
211.8%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-264
Disclosure4
2026-02-272
General1Patch1
2026-03-025
Disclosure1Patch4
2026-03-051
Patch1
2026-03-061
Disclosure1
2026-03-092
Disclosure2
2026-09-161
General1
Full discourse17 posts
  • HeroDevs@herodevs
    Patch

    🚨 New CVE Alert: CVE-2026-27739 (CVSS 9.2 – Critical) A critical SSRF and header injection vulnerability has been disclosed in Angular’s Server-Side Rendering (SSR) pipeline — and it’s more serious than it looks. The issue stems from Angular trusting user-controlled Host and X-Forwarded-* headers when reconstructing request URLs. An attacker can manipulate those headers to: • Redirect server-side API calls to attacker-controlled domains • Exfiltrate Authorization headers, API keys, or session cookies • Probe internal network resources (including cloud metadata endpoints) • Turn your SSR server into an open proxy This affects @angular/ssr versions prior to 19.2.21, 20.3.17, and 21.1.5. Angular 18 and below? No community patch available. If you’re running Angular SSR: ✔️ Patch immediately if you’re on a supported version ✔️ Implement strict header validation if you can’t upgrade ✔️ Or use HeroDevs Never-Ending Support (NES) for patched drop-in replacements on EOL versions This isn’t a misconfiguration. It’s a framework-level flaw in how SSR reconstructs request origins. If you are running Angular SSR on an end-of-life version (18.x and below), you need to act now. #Angular #CVE #AppSec #OpenSourceSecurity #SSRF #DevSecOps #HeroDevs

    Post summary

    A critical SSRF and header injection flaw in Angular SSR (CVE‑2026‑27739) has been disclosed, affecting specific early versions; urgent patching or mitigations such as strict header validation or HeroDevs NES replacements are advised.

    12020423
    2.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Angular Server-Side Rendering の脆弱性 CVE-2026-27739 が FIX:Web アプリに SSR の恐れ https://iototsecnews.jp/2026/03/02/angular-ssr-request-vulnerability-allows-attackers-to-trick-applications-into-sending-unauthorized-requests/ Angular Server-Side Rendering (SSR) に、内部リクエストを不正制御される深刻な脆弱性 CVE-2026-27739 (CVSS:9.2) が発見されました。Angular SSR において、Host や X-Forwarded-Host ヘッダを適切に検証せず、URL 再構築に使用していることに、この脆弱性は起因します。 これらのヘッダを細工する攻撃者は、アプリケーション内部の通信 (HttpClient など) の宛先を、外部の悪意のドメイン/内部の機密サーバ/クラウド・メタデータ・エンドポイントなどへ強制的にリダイレクトさせることができます。これにより、認証トークンやセッション Cookie の窃取/内部ネットワークの探索といった深刻な被害を招く恐れがあります。ご利用のチームは、ご注意ください。 #Angular #CVE202627739 #ServerSideRendering #Vulnerability

    Post summary

    The article announces the discovery of a severe SSR vulnerability (CVE‑2026‑27739) in Angular, detailing its technical root cause and potential impact on authentication tokens and internal network exposure.

    01011175
    483 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Angular patches a critical 9.2 CVSS SSRF vulnerability (CVE-2026-27739). Attackers can manipulate Host headers to steal credentials and probe internal networks. #Angular #SSRF #CyberSecurity #CVE202627739 #WebDev #InfoSec #Javascript #SecurityPatch https://securityonline.info/steering-the-server-critical-9-2-severity-ssrf-flaw-in-angular-ssr-allows-internal-network-probing/

    Post summary

    Angular has released a patch for CVE-2026-27739, a critical SSRF vulnerability that could allow attackers to manipulate Host headers to steal credentials and probe internal networks.

    01002365
    10.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2026-20127 3 - CVE-2025-59536 4 - CVE-2026-27509 5 - CVE-2026-27739 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers but provides no further technical details, exploit information, or mitigation guidance.

    00020314
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『When successfully exploited, this vulnerability allows for arbitrary internal request steering.』 CVE-2026-27739 Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline https://github.com/advisories/GHSA-x288-3778-4hhx

    Post summary

    The advisory announces that Angular SSR is vulnerable to SSRF and header injection, enabling arbitrary internal request steering.

    01010396
    6.7K followersView on X
  • Hugo Angulo@thermotronica
    General

    This is a non alert 🚨 https://nvd.nist.gov/vuln/detail/cve-2026-27739

    Post summary

    The post merely labels CVE-2026-27739 as a 'non alert' and links to its NVD page, without providing PoC, exploit, patch, or technical details.

    0000070
    2.9K followersView on X
  • ninp0@ninp0
    Disclosure

    CVE-2026-27739: Angular SSR Request Vulnerability Enabling Server-Side Request Forgery https://securityboulevard.com/2026/03/cve-2026-27739-angular-ssr-request-vulnerability-enabling-server-side-request-forgery/

    Post summary

    The text announces a newly disclosed Angular SSR vulnerability (CVE‑2026‑27739) that allows server‑side request forgery, but no details on PoC, exploitation, or patches are included.

    0000050
    494 followersView on X
  • Raymond Orta Forensic Document Examiner USA@ForensicDocExam
    Disclosure

    CVE-2026-27739: Angular SSR Request Vulnerability Enabling Server-Side Request Forgery https://ift.tt/wGifx4Q #forgery #forensic-document-examiner

    Post summary

    The tweet announces CVE-2026‑27739 as an Angular SSR vulnerability that permits SSRF, providing a brief technical description but no PoC, exploit code, patch details, or evidence of active exploitation.

    0000036
    2.7K followersView on X
  • Fernando Karl@fernandokarl
    Patch

    🚨 Atenção, desenvolvedores Angular! Uma falha crítica de SSR (CVE-2026-27739) permite requisitar servidores controlados por atacantes, expondo suas credenciais! Atualize imediatamente para as versões corrigidas e implemente validações rigorosas. 🛡️ #Cybersecurity #Angular #Vuls

    Post summary

    The post highlights a critical SSR vulnerability (CVE‑2026‑27739) in Angular, urging developers to update to patched versions and enforce strict validations to mitigate credential exposure.

    0000040
    255 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    Angular SSR vulnerability CVE-2026-27739 exposes apps to SSRF, allowing attackers to trick servers into sending unauthorized requests via flawed URL reconstruction. #Vulnerability https://threatcluster.io/cluster/critical-angular-ssr-vulnerability-enables-unauthorized-requ-4cb75ba9

    Post summary

    The post announces the Angular SSR vulnerability CVE-2026-27739, describing it as an SSRF flaw caused by flawed URL reconstruction, but it does not provide a PoC, exploit, or patch details.

    0000043
    86 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Angular SSR header-trust bug opens the door to SSRF and data exfil (CVE-2026-27739) Angular SSR can be manipulated into using attacker-supplied `Host`/`X-Forwarded-*` values to build the request origin, causing server-side fetches of relative URLs (via `HttpClient`) to resolve to attacker infrastructure—enabling internal probing and credential/cookie leakage. Patch to fixed Angular releases (21.2.0-rc.1 / 21.1.5 / 20.3.17 / 19.2.21) and enforce strict proxy/header validation. 🎯 Target: Global/Web apps using Angular SSR #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/angular-ssr-flaw/

    Post summary

    Angular SSR header‑trust bug (CVE‑2026‑27739) enables SSRF and data exfiltration; patches are available in specific Angular releases and strict header validation is recommended.

    0000044
    245 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Angular SSR “request URL” bug enables SSRF via trusted Host/X-Forwarded headers (CVE-2026-27739) Angular SSR can be tricked into reconstructing an attacker-controlled base origin by trusting `Host` and `X-Forwarded-*` headers, causing server-side requests (e.g., `HttpClient` relative URLs) to resolve to malicious endpoints—enabling credential/cookie exfiltration and internal network probing. Upgrade to patched versions (21.2.0-rc.1 / 21.1.5 / 20.3.17 / 19.2.21) and enforce strict header validation or avoid `req.headers` for URL construction. 🎯 Target: Global/Web apps using Angular SSR #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/angular-ssr-request-vulnerability/

    Post summary

    Angular SSR is vulnerable to SSRF through trusted Host/X‑Forwarded headers; upgrading to the specified patched versions and enforcing strict header validation mitigates the risk.

    0000044
    245 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical SSRF and Header Injection vulnerability (CVE-2026-27739) affects `@angular/ssr`. Patch to 21.2.0-rc.1 or later to mitigate risks. #AngularSSR #SSRF #Infosec https://www.pulsepatch.io/posts/cve-2026-27739-angular-ssr-ssrf-header-injection

    Post summary

    The announcement highlights a critical SSRF and Header Injection flaw in @angular/ssr, provides specific patch guidance to mitigate the risk, and offers technical details of the issue.

    0000061
    1 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27739 The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forge… https://www.cve.org/CVERecord?id=CVE-2026-27739 ----- Traducción: CVE-2026-27739 Ang… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑27739, a Server‑Side Request Forgery vulnerability affecting older Angular SSR versions, and links to the official CVE record.

    0000049
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27739 The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forge… https://www.cve.org/CVERecord?id=CVE-2026-27739

    Post summary

    The text announces CVE-2026-27739, a Server‑Side Request Forgery vulnerability affecting Angular SSR versions prior to 21.2.0‑rc.1, 21.1.5, 20.3.17, and 19.2.21.

    00000175
    56.6K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27739: Angular SSR: When 'Helpful' Headers Become Server-Side Sabotage A critical Server-Side Request Forgery (SSRF) vulnerability in Angular's Server-Side Rendering (SSR) pipeline turns the framework's URL reconstruction logic against itself... https://cvereports.com/reports/CVE-2026-27739

    Post summary

    The text announces a critical SSRF vulnerability in Angular's SSR pipeline, providing technical details but no PoC, exploit code, or patch information.

    0000045
    32 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27739 Server-Side Request Forgery (SSRF) Vulnerability in Angular SSR V... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27739 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A new SSRF vulnerability (CVE-2026-27739) in Angular SSR has been disclosed, providing basic technical details but no PoC, exploit, or patch information.

    0000055
    4.0K followersView on X

Explore more