Origin validation error in Angular - CVE-2026-50168

 

Origin validation error in Angular - CVE-2026-50168

Published: September 11, 2026


Vulnerability identifier: #VU149000
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50168
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and inject attacker-controlled content.

The vulnerability exists due to an origin validation error in the Angular SSR HTTP request interceptor (relativeUrlsTransformerInterceptorFn) when handling malformed request URLs. A remote attacker can send a request with a malformed Host header or absolute-form URI to disclose sensitive information and inject attacker-controlled content.

Exploitation requires server-side rendering with raw client URL inputs propagated to the rendering API, relative outbound HTTP requests, and the allowedHosts option enabled.


Affected software

Angular
webMethods API Gateway

How to mitigate CVE-2026-50168

Install security update from vendor's website.

Angular - addressed in versions 19.2.23, 20.3.22, 21.2.15, 22.0.0
webMethods API Gateway - update to 11.1 Fix13

External References

Related Security Bulletins