Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline
- Severity:
- High
Description
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Angular SSR request handling pipeline.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 16.2.0
References
- GHSA-x288-3778-4hhx
- angular.dev
- developer.mozilla.org
- CVE-2026-27739
- CWE-918
- CAPEC-310
- OWASP 2021-A10
- OWASP 2021-A6
Related Issues
- LangSmith Client SDK Affected by Server-Side Request Forgery via Tracing Header Injection - CVE-2026-25528
- lodash vulnerable to Code Injection via `_.template` imports key names - lodash-amd - CVE-2026-4800
- lodash vulnerable to Code Injection via `_.template` imports key names - lodash-es - CVE-2026-4800
- Axios: Header Injection via Prototype Pollution - CVE-2026-42035
You might also like:
- Tags:
- npm
- @nguniversal/common
Anything's wrong? Let us know Last updated on February 25, 2026


