Skip to content
Critical Angular SSR Vulnerability Enables Unauthorized Requests

Critical Angular SSR Vulnerability Enables Unauthorized Requests

First seen 2 Mar 2026, 10:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A critical vulnerability, tracked as CVE-2026-27739, has been identified in Angular Server-Side Rendering (SSR). This Server-Side Request Forgery (SSRF) flaw allows attackers to manipulate applications into sending unauthorized requests, affecting web applications using vulnerable versions of the Angular framework. The issue arises from Angular's internal URL reconstruction logic.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 211d ago How this analysis works

Timeline

2026-02-25
CVE-2026-27739 published
2026-03-02
Articles published detailing the vulnerability

More articles in this cluster (6)

Following this threat?

Track CVE-2026-27739 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed