DIRAS TAKE
Urgent: vulnerable Angular SSR code can cause SSRF that discloses attached server credentials and the facts show no fixed releases listed here; immediately reduce exposure of SSR endpoints and follow vendor guidance when patches are published.
What is CVE-2026-88056?
An attacker can cause server-side request forgery and exfiltrate server-side credentials from applications using Angular Server-Side Rendering in @angular/platform-server. CVE-2026-88056 affects multiple Angular releases: versions <= 19.2.25, and the ranges >= 20.0.0 and < 20.3.30, >= 21.0.0 and < 21.2.22, and >= 22.0.0 and < 22.1.4. The flaw occurs when user-controlled URLs are processed after a same-origin check and can convert relative paths into attacker-controlled origins; an attacker only needs to supply a crafted resource or request URL to trigger the issue in vulnerable apps. The weakness is classified as CWE-918 (Server-Side Request Forgery).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of angular angular are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| angular | <= 19.2.25 | |
| angular | >= 20.0.0, < 20.3.30 | |
| angular | >= 21.0.0, < 21.2.22 | |
| angular | >= 22.0.0, < 22.1.4 |
Is CVE-2026-88056 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-88056
- Restrict access to server-side rendering endpoints and block untrusted input from reaching server-side HTTP calls.
- Do not attach sensitive credentials (for example Authorization headers) to outbound requests initiated during SSR.
- Add defensive input handling: normalize and re-validate URLs server-side before resolving or making requests.
- Monitor server logs for unexpected outbound requests and implement network egress controls to prevent requests to unapproved destinations.
Frequently asked questions
Is CVE-2026-88056 being actively exploited?
There are no public reports of exploitation of CVE-2026-88056 as of 2026-09-30.
Which angular versions are affected by CVE-2026-88056?
Angular Server-Side Rendering is affected in versions <= 19.2.25 and in the ranges >= 20.0.0 and < 20.3.30, >= 21.0.0 and < 21.2.22, and >= 22.0.0 and < 22.1.4 as provided in the vendor-supplied affected data.
Is there a patch for CVE-2026-88056?
No fixed releases are listed in the provided affected records and patchAvailable is false; follow vendor advisories and apply updates when the vendor publishes fixed versions.
Does CVE-2026-88056 require authentication?
Exploitation relies on supplying a crafted resource or request URL to an affected Angular Server-Side Rendering application and does not require authentication per the supplied facts.
References
- nvd.nist.gov/vuln/detail/CVE-2026-88056
- cve.org/CVERecord?id=CVE-2026-88056
- github.com/angular/angular/security/advisories/GHSA-f6mr-pjwc-34m4
- github.com/angular/angular/commit/3e924cc8dbbb57f23b262cb8f0d7e2bd0673034c
- github.com/angular/angular/commit/5aa6d97deb9ef1de14e23748b7fa74f97d183132
- github.com/angular/angular/commit/71e52d1396b9cef98652929b73e08c4cde645970
- github.com/angular/angular/releases/tag/v20.3.30
- github.com/angular/angular/releases/tag/v21.2.22
- github.com/angular/angular/releases/tag/v22.1.4
- All angular CVEs on CVE Radar
- CVEs published in September 2026