CVE-2026-44437Disclosure(angular / angular_cli)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix header processing logic within Angular SSR. The internal validation mechanism fails to properly account for URL-encoded characters, specifically dots (%2e%2e). This allows an attacker to bypass security filters by injecting encoded path traversal sequences that are later decoded and utilized by the application logic. When an Angular SSR application is configured to trust proxy headers and is deployed behind a proxy that forwards the X-Forwarded-Prefix header without prior sanitization, an attacker can provide a payload such as /%2e%2e/evil. This vulnerability is fixed in19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-601

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular_cli

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
angular_cli

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 105-1305-14
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44437 Path Traversal via URL-Encoded Characters in Angular SSR X-Forwarded-Prefix Header https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44437

    Post summary

    A path traversal vulnerability (CVE-2026-44437) in Angular SSR’s X-Forwarded-Prefix header caused by URL-encoded characters has been disclosed.

    0000047
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44437 The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability ex… https://www.cve.org/CVERecord?id=CVE-2026-44437

    Post summary

    The snippet announces CVE-2026-44437, listing the Angular SSR versions impacted, but offers no further disclosure such as a PoC, exploit, or mitigation advice.

    0000091
    57.5K followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appangularangular_cli-node.js-
Appangularangular_cli22.0.0node.js-
Appangularangular_cli22.0.0node.js-
Appangularangular_cli22.0.0node.js-
Appangularangular_cli22.0.0node.js-
Appangularangular_cli22.0.0node.js-
Appangularangular_cli22.0.0node.js-
Appangularangular_cli22.0.0node.js-

Explore more