CVE-2026-33397
medium
CVSS v3
6.1
CVSS v4 NEW
6.9
VIR risk
6.1
Description
Protocol-Relative URL Injection via Single Backslash Bypass in Angular SSR
Predictions
Exploit likelihood
71%
Patch ETA
โ
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| npm | @angular/ssr | >=22.0.0-next.0,<22.0.0-next.2 | 22.0.0-next.2 |
| npm | @angular/ssr | >=21.0.0-next.0,<21.2.3 | 21.2.3 |
| npm | @angular/ssr | >=20.0.0-next.0,<20.3.21 | 20.3.21 |
| NPM | @angular/ssr | >= 20.0.0-next.0, < 20.3.21 | 20.3.21 |
| NPM | @angular/ssr | >= 21.0.0-next.0, < 21.2.3 | 21.2.3 |
| NPM | @angular/ssr | >= 22.0.0-next.0, < 22.0.0-next.2 | 22.0.0-next.2 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| angular | angular_cli | {"startIncluding":"20.0.0","endExcluding":"20.3.21"} | 20.3.21 |
| angular | angular_cli | 22.0.0 | |
References
- https://github.com/advisories/GHSA-xh43-g2fq-wjrj
- https://github.com/angular/angular-cli/pull/32771
- https://github.com/angular/angular-cli/security/advisories/GHSA-vfx2-hv2g-xj5f
- https://nvd.nist.gov/vuln/detail/CVE-2026-33397
- https://github.com/angular/angular-cli
- https://github.com/advisories/GHSA-vfx2-hv2g-xj5f
CWEs
CWE-601
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.