CVE-2026-46417
angular angular, Red Hat Enterprise Linux 8, Red Hat Fuse 7
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server. The issue stems from how the server-side rendering (SSR) engine processes the request URL provided to the rendering entry points. When an absolute-form URL (e.g., http://evil.com) is passed to the rendering engine, the internal ServerPlatformLocation can be manipulated into adopting the attacker-controlled domain as the...
- CVSS
- 8.8
- EPSS
- 0.22% 12.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.23