Origin validation error in Angular - CVE-2026-50168
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and inject attacker-controlled content.
The vulnerability exists due to an origin validation error in the Angular SSR HTTP request interceptor (relativeUrlsTransformerInterceptorFn) when handling malformed request URLs. A remote attacker can send a request with a malformed Host header or absolute-form URI to disclose sensitive information and inject attacker-controlled content.
Exploitation requires server-side rendering with raw client URL inputs propagated to the rendering API, relative outbound HTTP requests, and the allowedHosts option enabled.
Affected software
webMethods API Gateway
How to mitigate CVE-2026-50168
webMethods API Gateway - update to 11.1 Fix13