{"id":"CVE-2026-33397","summary":"Angular SSR Vulnerable to Protocol-Relative URL Injection via Single Backslash Bypass","details":"The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-next.2, the 21.x branch prior to 21.2.3, and the 20.x branch prior to 20.3.21 have an Open Redirect vulnerability in `@angular/ssr` due to an incomplete fix for CVE-2026-27738. While the original fix successfully blocked multiple leading slashes (e.g., `///`), the internal validation logic fails to account for a single backslash (`\\`) bypass. When an Angular SSR application is deployed behind a proxy that passes the `X-Forwarded-Prefix` header, an attacker provides a value starting with a single backslash, the internal validation failed to flag the single backslash as invalid, the application prepends a leading forward slash, resulting in a `Location` header containing the URL, and modern browsers interpret the `/\\` sequence as `//`, treating it as a protocol-relative URL and redirecting the user to the attacker-controlled domain. Furthermore, the response lacks the `Vary: X-Forwarded-Prefix` header, allowing the malicious redirect to be stored in intermediate caches (Web Cache Poisoning). Versions 22.0.0-next.2, 21.2.3, and 20.3.21 contain a patch. Until the patch is applied, developers should sanitize the `X-Forwarded-Prefix` header in their `server.ts` before the Angular engine processes the request.","aliases":["GHSA-vfx2-hv2g-xj5f"],"modified":"2026-08-12T03:51:34.756360648Z","published":"2026-03-26T13:46:16.145Z","related":["GHSA-vfx2-hv2g-xj5f","GHSA-xh43-g2fq-wjrj"],"database_specific":{"cwe_ids":["CWE-601"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33397.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33397.json"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xh43-g2fq-wjrj"},{"type":"ADVISORY","url":"https://github.com/angular/angular-cli/security/advisories/GHSA-vfx2-hv2g-xj5f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33397"},{"type":"FIX","url":"https://github.com/angular/angular-cli/pull/32771"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/angular/angular-cli","events":[{"introduced":"510db3e93f6aa8daccc80dd0fcbc4dd0c3a3fcec"},{"fixed":"34d524549b68912f8ebe4e656a342b797161d232"},{"introduced":"a06ccb3f5f20364bfd0ff47269ac63824652d118"},{"fixed":"ec8a04b9513cbabf7412ac20b7fdbab2e9faa166"},{"introduced":"93b1debc57ff7298be616469cdefe94f215c43be"},{"last_affected":"174c7860b212d2f4f78ad7275e5e33f0f17487fd"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:angular:angular_cli:*:-:*:*:*:node.js:*:*","cpe:2.3:a:angular:angular_cli:22.0.0:next0:*:*:*:node.js:*:*","cpe:2.3:a:angular:angular_cli:22.0.0:next1:*:*:*:node.js:*:*"],"extracted_events":[{"introduced":"20.0.0"},{"fixed":"20.3.21"},{"introduced":"21.0.0"},{"fixed":"21.2.3"},{"introduced":"22.0.0-next0"},{"last_affected":"22.0.0-next0"},{"introduced":"22.0.0-next1"},{"last_affected":"22.0.0-next1"}]}}],"versions":["22.0.0-next0","22.0.0-next1","v22.0.0-next.1","v22.0.0-next.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33397.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}