Vulnerabilities/

Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline

Severity:
High

Description

A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Angular SSR request handling pipeline.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@nguniversal/common
Anything's wrong? Let us know Last updated on February 25, 2026