{"id":"GHSA-f6mr-pjwc-34m4","summary":"Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR","details":"### Summary\nA discrepancy between WHATWG URL parsing and Angular SSR's URL resolution allows attackers to bypass same-origin checks and cause Server-Side Request Forgery (SSRF), potentially leaking sensitive server-side credentials.\n\n### Technical Description\nWhen applications validate incoming URLs using the WHATWG URL standard (`new URL(input, trustedOrigin)`), Unicode whitespace characters (such as NO-BREAK SPACE `U+00A0` or ZERO WIDTH NO-BREAK SPACE `U+FEFF`) are not stripped and are evaluated as part of a same-origin relative path (e.g. `http://trusted-origin/%C2%A0//attacker.example/collect`). Consequently, these URLs successfully pass application-level same-origin checks.\n\nHowever, `@angular/platform-server`'s URL resolution utility (`resolveUrl` / `parseUrl`) previously executed `String.prototype.trim()`. Because JavaScript's `String.prototype.trim()` strips all Unicode whitespace (including `U+00A0`), the leading non-breaking space was removed, converting the string into a cross-origin protocol-relative URL (`//attacker.example/collect`). When resolved during server-side rendering (such as in `relativeUrlsTransformerInterceptorFn`), this caused the HTTP request to be dispatched to the attacker-controlled origin (`http://attacker.example/collect`), leaking any credentials (such as `Authorization` headers) attached by the application for the intended same-origin request.\n\n### Impact & Reachability\n* **Reachability**: The vulnerability affects Angular Server-Side Rendering (SSR) applications where user-controlled input influences resource or request URLs processed by Angular's `HttpClient`, an application-level same-origin check is performed before dispatching, and sensitive server-side credentials (such as API keys or Bearer tokens) are attached to approved requests.\n* **Impact**: Successful exploitation allows attackers to bypass same-origin validation, triggering Server-Side Request Forgery (SSRF) and leaking sensitive server-side credentials attached to the request.\n\n\n**Proof of Concept:**\n```ts\n// Interceptor performing same-origin validation\nconst trustedOrigin = new URL('http://localhost:4000/');\nconst target = new URL(req.urlWithParams, trustedOrigin);\n\nif (target.origin !== trustedOrigin.origin) {\n  throw new Error('Cross-origin request blocked');\n}\n\n// Request passes validation, server attaches sensitive credential:\nconst authenticatedReq = req.clone({\n  headers: req.headers.set('Authorization', 'Bearer SERVER-SECRET-TOKEN'),\n});\n\n// @angular/platform-server previously trimmed the URL, converting it into\n// //attacker.example/collect and routing the credential to the attacker.\n```\n\n### Workarounds\n* Validate and sanitize input URLs to disallow leading Unicode whitespace characters (such as `\\u00A0`) before performing origin checks or passing them to `HttpClient`.\n* Avoid relying solely on `new URL(input, trustedOrigin).origin` for authorization if the input string may be trimmed or processed by utilities that normalize whitespace differently from the WHATWG URL standard.","aliases":["CVE-2026-88056"],"modified":"2026-09-10T20:30:04.442574905Z","published":"2026-09-10T20:19:43Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-10T20:19:43Z","nvd_published_at":null,"cwe_ids":["CWE-918"]},"references":[{"type":"WEB","url":"https://github.com/angular/angular/security/advisories/GHSA-f6mr-pjwc-34m4"},{"type":"WEB","url":"https://github.com/angular/angular/commit/3e924cc8dbbb57f23b262cb8f0d7e2bd0673034c"},{"type":"WEB","url":"https://github.com/angular/angular/commit/5aa6d97deb9ef1de14e23748b7fa74f97d183132"},{"type":"WEB","url":"https://github.com/angular/angular/commit/71e52d1396b9cef98652929b73e08c4cde645970"},{"type":"WEB","url":"https://github.com/angular/angular/commit/9339a7a2de437ed93f9cc3da7f32d0100412d599"},{"type":"PACKAGE","url":"https://github.com/angular/angular"},{"type":"WEB","url":"https://github.com/angular/angular/releases/tag/v20.3.30"},{"type":"WEB","url":"https://github.com/angular/angular/releases/tag/v21.2.22"},{"type":"WEB","url":"https://github.com/angular/angular/releases/tag/v22.1.4"}],"affected":[{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"22.0.0"},{"fixed":"22.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f6mr-pjwc-34m4/GHSA-f6mr-pjwc-34m4.json"}},{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.0.0"},{"fixed":"21.2.22"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f6mr-pjwc-34m4/GHSA-f6mr-pjwc-34m4.json"}},{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0"},{"fixed":"20.3.30"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f6mr-pjwc-34m4/GHSA-f6mr-pjwc-34m4.json"}},{"package":{"name":"@angular/platform-server","ecosystem":"npm","purl":"pkg:npm/%40angular/platform-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"19.2.25"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f6mr-pjwc-34m4/GHSA-f6mr-pjwc-34m4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}