| Summary | The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix header processing logic within Angular SSR. The internal validation mechanism fails to properly account for URL-encoded characters, specifically dots (%2e%2e). This allows an attacker to bypass security filters by injecting encoded path traversal sequences that are later decoded and utilized by the application logic. |
|---|---|
| Publication Date | May 14, 2026, 7:16 a.m. |
| Registration Date | May 15, 2026, 4:23 a.m. |
| Last Update | May 15, 2026, 3:17 a.m. |