@angular/platform-server: SSRF via Hostname Hijacking (CVE-2026-46417)
A Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server versions up to 18.2.14. The vulnerability allows an attacker to manipulate the server-side rendering engine's hostname by passing an absolute URL, causing relative HTTP requests to be redirected to attacker-controlled domains. This can expose internal APIs or metadata services. The issue is mitigated by an allowlist mechanism introduced in versions 19.2.22, 20.3.21, 21.2.13, and 22.0.0-next.12, which validates hostnames before rendering. Developers unable to upgrade immediately should implement strict URL validation in their server entry points.
AI Analysis
Technical Summary
CVE-2026-46417 is an SSRF vulnerability in @angular/platform-server affecting versions up to 18.2.14. The vulnerability arises because the server-side rendering engine's ServerPlatformLocation can be hijacked by passing an absolute-form URL, causing the internal hostname to be set to an attacker-controlled domain. This leads to relative HttpClient requests and PlatformLocation.hostname references being redirected to malicious servers, potentially exposing sensitive internal resources. The vulnerability is addressed by adding an allowedHosts configuration option to the renderModule and renderApplication functions, which restricts hostnames to a trusted allowlist. Patch versions include 19.2.22, 20.3.21, 21.2.13, and 22.0.0-next.12. Workarounds involve validating or normalizing request URLs before rendering to prevent hostname hijacking.
Potential Impact
An attacker can cause the server-side rendering engine to redirect internal HTTP requests to attacker-controlled domains by manipulating the hostname. This can lead to exposure of internal APIs or metadata services that rely on relative URLs, potentially compromising sensitive information or internal infrastructure.
Mitigation Recommendations
Official patches are available in versions 19.2.22, 20.3.21, 21.2.13, and 22.0.0-next.12 of @angular/platform-server. Users should upgrade to one of these versions to mitigate the vulnerability. For those unable to upgrade immediately, implement strict URL validation or normalization in the server entry point to ensure that only trusted hostnames are processed by the rendering engine. For example, validate the request host header against a trusted list and reject requests from untrusted hosts before calling renderApplication or renderModule.
@angular/platform-server: SSRF via Hostname Hijacking (CVE-2026-46417)
Description
A Server-Side Request Forgery (SSRF) vulnerability exists in @angular/platform-server versions up to 18.2.14. The vulnerability allows an attacker to manipulate the server-side rendering engine's hostname by passing an absolute URL, causing relative HTTP requests to be redirected to attacker-controlled domains. This can expose internal APIs or metadata services. The issue is mitigated by an allowlist mechanism introduced in versions 19.2.22, 20.3.21, 21.2.13, and 22.0.0-next.12, which validates hostnames before rendering. Developers unable to upgrade immediately should implement strict URL validation in their server entry points.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-46417 is an SSRF vulnerability in @angular/platform-server affecting versions up to 18.2.14. The vulnerability arises because the server-side rendering engine's ServerPlatformLocation can be hijacked by passing an absolute-form URL, causing the internal hostname to be set to an attacker-controlled domain. This leads to relative HttpClient requests and PlatformLocation.hostname references being redirected to malicious servers, potentially exposing sensitive internal resources. The vulnerability is addressed by adding an allowedHosts configuration option to the renderModule and renderApplication functions, which restricts hostnames to a trusted allowlist. Patch versions include 19.2.22, 20.3.21, 21.2.13, and 22.0.0-next.12. Workarounds involve validating or normalizing request URLs before rendering to prevent hostname hijacking.
Potential Impact
An attacker can cause the server-side rendering engine to redirect internal HTTP requests to attacker-controlled domains by manipulating the hostname. This can lead to exposure of internal APIs or metadata services that rely on relative URLs, potentially compromising sensitive information or internal infrastructure.
Mitigation Recommendations
Official patches are available in versions 19.2.22, 20.3.21, 21.2.13, and 22.0.0-next.12 of @angular/platform-server. Users should upgrade to one of these versions to mitigate the vulnerability. For those unable to upgrade immediately, implement strict URL validation or normalization in the server entry point to ensure that only trusted hostnames are processed by the rendering engine. For example, validate the request host header against a trusted list and reject requests from untrusted hosts before calling renderApplication or renderModule.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-rfh7-fxqc-q52v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-46417"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a58b41068715ace43d67d6f
Added to database: 07/16/2026, 10:36:00 UTC
Last enriched: 07/16/2026, 10:53:19 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.