CVE-2026-33397 Details
Description
The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-next.2, the 21.x branch prior to 21.2.3, and the 20.x branch prior to 20.3.21 have an Open Redirect vulnerability in `@angular/ssr` due to an incomplete fix for CVE-2026-27738. While the original fix successfully blocked multiple leading slashes (e.g., `///`), the internal validation logic fails to account for a single backslash (`\`) bypass. When an Angular SSR application is deployed behind a proxy that passes the `X-Forwarded-Prefix` header, an attacker provides a value starting with a single backslash, the internal validation failed to flag the single backslash as invalid, the application prepends a leading forward slash, resulting in a `Location` header containing the URL, and modern browsers interpret the `/\` sequence as `//`, treating it as a protocol-relative URL and redirecting the user to the attacker-controlled domain. Furthermore, the response lacks the `Vary: X-Forwarded-Prefix` header, allowing the malicious redirect to be stored in intermediate caches (Web Cache Poisoning). Versions 22.0.0-next.2, 21.2.3, and 20.3.21 contain a patch. Until the patch is applied, developers should sanitize the `X-Forwarded-Prefix` header in their `server.ts` before the Angular engine processes the request.
A vulnerability allowing open redirects has been identified in Angular Server-Side Rendering (SSR) applications. This issue affects versions 22.x prior to 22.0.0-next.2, 21.x prior to 21.2.3, and 20.x prior to 20.3.21. The vulnerability arises from an incomplete fix for a previous open redirect issue, allowing attackers to manipulate the X-Forwarded-Prefix header to inject malicious URLs. When the application normalizes the URL, it inadvertently creates a protocol-relative URL that redirects users to an attacker-controlled domain. Additionally, the lack of a Vary: X-Forwarded-Prefix header in the response enables web cache poisoning, storing the malicious redirect in intermediate caches.
Update to Angular SSR versions 22.0.0-next.2, 21.2.3, or 20.3.21. If an immediate update is not possible, sanitize the X-Forwarded-Prefix header in the server.ts file before the Angular engine processes the request.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/advisories/GHSA-xh43-g2fq-wjrj | [email protected] | Not Applicable |
| https://github.com/angular/angular-cli/pull/32771 | [email protected] | Issue TrackingPatch |
| https://github.com/angular/angular-cli/security/advisories/GHSA-vfx2-hv2g-xj5f | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| angular angular cli | >= 20.0.0, < 20.3.21 >= 21.0.0, < 21.2.3 22.0.0 next0 22.0.0 next1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 30, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |