GHSA-xh43-g2fq-wjrj

Suggest an improvement
Source
https://github.com/advisories/GHSA-xh43-g2fq-wjrj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-xh43-g2fq-wjrj/GHSA-xh43-g2fq-wjrj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xh43-g2fq-wjrj
Aliases
Related
Published
2026-02-25T22:41:57Z
Modified
2026-04-02T13:44:28Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Angular SSR has an Open Redirect via X-Forwarded-Prefix
Details

An Open Redirect vulnerability exists in the internal URL processing logic in Angular SSR. The logic normalizes URL segments by stripping leading slashes; however, it only removes a single leading slash.

When an Angular SSR application is deployed behind a proxy that passes the X-Forwarded-Prefix header, an attacker can provide a value starting with three slashes (e.g., ///evil.com).

  1. The application processes a redirect (e.g., from a router redirectTo or i18n locale switch).
  2. Angular receives ///evil.com as the prefix.
  3. It strips one slash, leaving //evil.com.
  4. The resulting string is used in the Location header.
  5. Modern browsers interpret // as a protocol-relative URL, redirecting the user from https://your-app.com to https://evil.com.

Impact

This vulnerability allows attackers to conduct large-scale phishing and SEO hijacking:

  • Scale: A single request can poison a high-traffic route, impacting all users until the cache expires.
  • SEO Poisoning: Search engine crawlers may follow and index these malicious redirects, causing the legitimate site to be delisted or associated with malicious domains.
  • Trust: Because the initial URL belongs to the trusted domain, users and security tools are less likely to flag the redirect as malicious.

Attack Preconditions

  • The application must use Angular SSR.
  • The application must have routes that perform internal redirects.
  • The infrastructure (Reverse Proxy/CDN) must pass the X-Forwarded-Prefix header to the SSR process without sanitization.
  • The cache must not vary on the X-Forwarded-Prefix header.

Patches

  • 21.2.0-rc.1
  • 21.1.5
  • 20.3.17
  • 19.2.21

Workarounds

Until the patch is applied, developers should sanitize the X-Forwarded-Prefix header in theirserver.ts before the Angular engine processes the request:

app.use((req, res, next) => {
  const prefix = req.headers['x-forwarded-prefix']?.trim();
  if (prefix) {
    // Sanitize by removing all leading slashes
    req.headers['x-forwarded-prefix'] = prefix.replace(/^[/\\]+/, '/');
  }
  next();
});

Resources

Database specific
{
    "cwe_ids":  [
        "CWE-601"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-25T22:41:57Z",
    "nvd_published_at":  "2026-02-25T17:25:40Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / @angular/ssr

Package

Name
@angular/ssr
View open source insights on deps.dev
Purl
pkg:npm/%40angular/ssr

Affected ranges

Type
SEMVER
Events
Introduced
21.2.0-next.0
Fixed
21.2.0-rc.1

Database specific

last_known_affected_version_range
"< 21.2.0-rc.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-xh43-g2fq-wjrj/GHSA-xh43-g2fq-wjrj.json"

npm / @angular/ssr

Package

Name
@angular/ssr
View open source insights on deps.dev
Purl
pkg:npm/%40angular/ssr

Affected ranges

Type
SEMVER
Events
Introduced
21.0.0-next.0
Fixed
21.1.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-xh43-g2fq-wjrj/GHSA-xh43-g2fq-wjrj.json"

npm / @angular/ssr

Package

Name
@angular/ssr
View open source insights on deps.dev
Purl
pkg:npm/%40angular/ssr

Affected ranges

Type
SEMVER
Events
Introduced
20.0.0-next.0
Fixed
20.3.17

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-xh43-g2fq-wjrj/GHSA-xh43-g2fq-wjrj.json"

npm / @angular/ssr

Package

Name
@angular/ssr
View open source insights on deps.dev
Purl
pkg:npm/%40angular/ssr

Affected ranges

Type
SEMVER
Events
Introduced
19.0.0-next.0
Fixed
19.2.21

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-xh43-g2fq-wjrj/GHSA-xh43-g2fq-wjrj.json"