@angular/ssr
npm6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @angular/ssrpage 1 of 1
- CVE-2025-59052HIGHCVSS 7.1EG 0.0✓ Fixed in 21.0.0-next.32025-09-10
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Angular uses a DI container (the "platform injector") to hold request-specific state during server-side ren…
- CVE-2025-62427HIGHCVSS 8.7EG 0.0✓ Fixed in 21.0.0-next.82025-10-16
The Angular SSR is a server-rise rendering tool for Angular applications. The vulnerability is a Server-Side Request Forgery (SSRF) flaw within the URL resolution mechanism of Angular's Server-Side Rendering package (@angular/ssr) before 1…
- CVE-2026-27738NONECVSS 0.0EG 0.0✓ Fixed in 19.2.212026-02-25
The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the…
- CVE-2026-27739NONECVSS 0.0EG 0.0✓ Fixed in 19.2.212026-02-25
The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forgery (SSRF) vulnerability in the Angular SSR request handling pipeline. The…
- CVE-2026-33397MEDIUMCVSS 6.1EG 6.1✓ Fixed in 20.3.212026-03-26
The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-next.2, the 21.x branch prior to 21.2.3, and the 20.x branch prior to 20.3.21 have an Open Redirect vulnerability in `@an…
- CVE-2026-44437MEDIUMCVSS 6.1EG 6.1✓ Fixed in 19.2.252026-05-13
The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix header processing logic within Angular SSR…
Check whether @angular/ssr is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @angular/ssr CVEs against the assets you own.
Start Free Scan →