An Open Redirect vulnerability exists in the internal URL processing logic in Angular SSR. The logic normalizes URL segments by stripping leading slashes; however, it only removes a single leading slash.
When an Angular SSR application is deployed behind a proxy that passes the X-Forwarded-Prefix header, an attacker can provide a value starting with three slashes (e.g., ///evil.com).
redirectTo or i18n locale switch).///evil.com as the prefix.//evil.com.Location header.// as a protocol-relative URL, redirecting the user from https://your-app.com to https://evil.com.This vulnerability allows attackers to conduct large-scale phishing and SEO hijacking:
X-Forwarded-Prefix header to the SSR process without sanitization.X-Forwarded-Prefix header.Until the patch is applied, developers should sanitize the X-Forwarded-Prefix header in theirserver.ts before the Angular engine processes the request:
app.use((req, res, next) => {
const prefix = req.headers['x-forwarded-prefix']?.trim();
if (prefix) {
// Sanitize by removing all leading slashes
req.headers['x-forwarded-prefix'] = prefix.replace(/^[/\\]+/, '/');
}
next();
});
{
"cwe_ids": [
"CWE-601"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-25T22:41:57Z",
"nvd_published_at": "2026-02-25T17:25:40Z",
"severity": "MODERATE"
}