« Volver al listado

CVE-2026-50168

Estado: AnalizadaAlta (8.8)—

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allows remote attackers to bypass host allowlist constraints and direct server-side outgoing requests to arbitrary external endpoints. This occurs due to a parser differential between the strict WHATWG URL parser used for allowlist validation and the lenient Domino URL parser used to initialize the server emulated DOM.

Leer descripción completaMostrar menos

When a server-side request contains a malformed URL with a double port structure (e.g., http://evil.com:80:80/path), Node's strict URL.canParse(url) logic returns false and skips host check validation entirely. However, the same malformed URL is later accepted and parsed leniently by Domino's internal parser, which resolves the origin to http://evil.com:80. The Angular SSR HTTP request interceptor (relativeUrlsTransformerInterceptorFn) then resolves all relative backend HTTP requests against this adopted origin, executing the SSRF attack. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de aplicación web expuesta (Angular SSR) explotable remotamente sin autenticación (AV:N, PR:N, UI:N). SSRF resultante mediante bypass de validación de URL permite redirigir solicitudes a endpoints externos arbitrarios, cumpliendo T1090.004 (proxy inverso/SSRF).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-50168",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-50168",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-22T17:59:41.275571Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.8,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "LOW",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "angular",
          "product": "angular",
          "versions": [
            {
              "status": "affected",
              "version": ">= 22.0.0-next.0, < 22.0.0-rc.2"
            },
            {
              "status": "affected",
              "version": ">= 21.0.0-next.0, < 21.2.15"
            },
            {
              "status": "affected",
              "version": ">= 20.0.0-next.0, < 20.3.22"
            },
            {
              "status": "affected",
              "version": ">= 19.0.0-next.0, < 19.2.23"
            },
            {
              "status": "affected",
              "version": "<= 18.2.14"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-22T18:16:42.117",
  "references": [
    {
      "url": "https://github.com/angular/angular/pull/68928",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/angular/angular/security/advisories/GHSA-xrxm-cp7j-8xf6",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        },
        {
          "lang": "en",
          "value": "CWE-918"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/platform-server package allows remote attackers to bypass host allowlist constraints and direct server-side outgoing requests to arbitrary external endpoints. This occurs due to a parser differential between the strict WHATWG URL parser used for allowlist validation and the lenient Domino URL parser used to initialize the server emulated DOM. When a server-side request contains a malformed URL with a double port structure (e.g., http://evil.com:80:80/path), Node's strict URL.canParse(url) logic returns false and skips host check validation entirely. However, the same malformed URL is later accepted and parsed leniently by Domino's internal parser, which resolves the origin to http://evil.com:80. The Angular SSR HTTP request interceptor (relativeUrlsTransformerInterceptorFn) then resolves all relative backend HTTP requests against this adopted origin, executing the SSRF attack. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23."
    }
  ],
  "lastModified": "2026-07-09T15:24:54.253",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "939DF9D7-8867-439B-B06E-FF9D1450057D",
              "versionEndIncluding": "18.2.14",
              "versionStartIncluding": "2.0.0"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AF8FC47-F9CA-48DC-88C4-51ECA89577A7",
              "versionEndExcluding": "19.2.23",
              "versionStartIncluding": "19.0.0"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6594675A-6A09-4550-AF8B-C9E25CCFE022",
              "versionEndExcluding": "20.3.22",
              "versionStartIncluding": "20.0.0"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C446A761-4FD9-43B8-8EF2-8A23EC2091DF",
              "versionEndExcluding": "21.2.15",
              "versionStartIncluding": "21.0.0"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next0:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "71DA6BB7-D67B-431B-A4BB-792DEC51C980"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01F108F8-1BC4-4E33-BB49-646C118CA697"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next10:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C5388FC5-DA5B-4C27-B868-E0D8BAD2EB28"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next11:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A18EA1D-24C0-43F7-B73B-562F86E3A46E"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next12:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B59DAA7F-A7B5-4687-96B0-10CD61165910"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19366888-B58B-4AEE-B99C-CBB26CCF9AA5"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D22F98A2-DB7A-41D2-AAA0-90D8AE707267"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next4:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D19C89E-9D61-4DBD-8CA5-5F317691E1B6"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next5:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6E69821-B1AB-4FE8-9245-74775E86D346"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next6:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E7096357-4623-475F-A015-ADB8EE2B450F"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next7:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A81F04C2-2824-40B9-B7F8-B27E6DF21403"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next8:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0002A01-F19D-47F3-94EA-C3423EC763E6"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:next9:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7499CFC4-AAA5-461E-909F-0E514CFD5DA1"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:rc0:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A781EF8-8ADA-4960-B839-0064607D36AE"
            },
            {
              "criteria": "cpe:2.3:a:angular:angular:22.0.0:rc1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4775F816-6599-44D3-BD0F-9C843AB37DF3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}