CVE-2026-88056: server-side request forgery in angular angular

An attacker can cause server-side request forgery and exfiltrate server-side credentials from applications using Angular Server-Side Rendering in @angular/platform-server. CVE-2026-88056 affects multiple Angular releases: versions <= 19.2.25, and the ranges >= 20.0.0 and < 20.3.30, >= 21.0.0 and < 21.2.22, and >= 22.0.0 and < 22.1.4. The flaw occurs when user-controlled URLs are processed after a same-origin check and can convert relative paths into attacker-controlled origins; an attacker only needs to supply a crafted resource or request URL to trigger the issue in vulnerable apps.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.1CRITICAL
EPSS
0.00613
CWE
CWE-918
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: vulnerable Angular SSR code can cause SSRF that discloses attached server credentials and the facts show no fixed releases listed here; immediately reduce exposure of SSR endpoints and follow vendor guidance when patches are published.

What is CVE-2026-88056?

An attacker can cause server-side request forgery and exfiltrate server-side credentials from applications using Angular Server-Side Rendering in @angular/platform-server. CVE-2026-88056 affects multiple Angular releases: versions <= 19.2.25, and the ranges >= 20.0.0 and < 20.3.30, >= 21.0.0 and < 21.2.22, and >= 22.0.0 and < 22.1.4. The flaw occurs when user-controlled URLs are processed after a same-origin check and can convert relative paths into attacker-controlled origins; an attacker only needs to supply a crafted resource or request URL to trigger the issue in vulnerable apps. The weakness is classified as CWE-918 (Server-Side Request Forgery).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of angular angular are affected?

BRANCHAFFECTEDFIXED
angular<= 19.2.25
angular>= 20.0.0, < 20.3.30
angular>= 21.0.0, < 21.2.22
angular>= 22.0.0, < 22.1.4

Is CVE-2026-88056 being exploited?

There are no public reports of exploitation as of 2026-09-30.

How to fix CVE-2026-88056

  1. Restrict access to server-side rendering endpoints and block untrusted input from reaching server-side HTTP calls.
  2. Do not attach sensitive credentials (for example Authorization headers) to outbound requests initiated during SSR.
  3. Add defensive input handling: normalize and re-validate URLs server-side before resolving or making requests.
  4. Monitor server logs for unexpected outbound requests and implement network egress controls to prevent requests to unapproved destinations.

Frequently asked questions

Is CVE-2026-88056 being actively exploited?

There are no public reports of exploitation of CVE-2026-88056 as of 2026-09-30.

Which angular versions are affected by CVE-2026-88056?

Angular Server-Side Rendering is affected in versions <= 19.2.25 and in the ranges >= 20.0.0 and < 20.3.30, >= 21.0.0 and < 21.2.22, and >= 22.0.0 and < 22.1.4 as provided in the vendor-supplied affected data.

Is there a patch for CVE-2026-88056?

No fixed releases are listed in the provided affected records and patchAvailable is false; follow vendor advisories and apply updates when the vendor publishes fixed versions.

Does CVE-2026-88056 require authentication?

Exploitation relies on supplying a crafted resource or request URL to an affected Angular Server-Side Rendering application and does not require authentication per the supplied facts.

References