Angular < 20.3.33 Multiple Vulnerabilities

medium Web App Scanning Plugin ID 115568

Synopsis

Angular < 20.3.33 Multiple Vulnerabilities

Description

According to its self-reported version number, Angular is prior to 20.0.0, 20.x prior to 20.3.33, 21.x prior to 21.2.25 or 22.x prior to 22.2.1. It is, therefore, affected by multiple vulnerabilities:

- An open redirect vulnerability in @angular/platform-server when Server-Side Rendering (SSR) is enabled. A request URL containing a popping dot-segment followed by multiple slashes (such as /.//evil.test) bypasses the protocol-relative URL check performed before URL normalization, causing the SSR engine to emit a redirect to an attacker-controlled external domain. (GHSA-w739-gvwx-grc3)

- A denial of service vulnerability in @angular/router when Server-Side Rendering (SSR) is enabled and RouterLink directives use the merge or preserve query parameters handling. Each rendered link retains a copy of the incoming request query parameters until the SSR response completes, allowing an unauthenticated remote attacker to exhaust the Node.js memory heap with crafted query strings. This issue only affects versions 21.2.0 and later. (GHSA-57xq-rjx2-v5xh)

- A denial of service vulnerability in @angular/router when Server-Side Rendering (SSR) is enabled. The router does not reject unconfigured empty-path auxiliary outlet segments during route matching, allowing an unauthenticated remote attacker to send URLs with many crafted outlet segments to exhaust the Node.js memory heap or CPU resources. (GHSA-62vg-58rm-qff7)

Note that the scanner has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Angular version 20.3.33 or later.

See Also

https://github.com/angular/angular/security/advisories/GHSA-57xq-rjx2-v5xh

https://github.com/angular/angular/security/advisories/GHSA-62vg-58rm-qff7

https://github.com/angular/angular/security/advisories/GHSA-w739-gvwx-grc3

Plugin Details

Severity: Medium

ID: 115568

Type: Version Based

Published: 10/2/2026

Updated: 10/2/2026

Scan Template: basic, full, pci, scan

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.1

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:C

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS Score Source: Tenable

Vulnerability Information

CPE: cpe:2.3:a:angular:angular:*:*:*:*:*:*:*:*

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/30/2026

Reference Information