Angular — CWE-601

All FrameworksAngularCWE-601

2 CVEs categorized as CWE-601 — URL Redirection to Untrusted Site (Open Redirect) in Angular.

CVE-2026-33397MEDIUM2026
The Angular SSR is a server-rise rendering tool for Angular applications. Versions on the 22.x branch prior to 22.0.0-next.2, the 21.x branch prior to 21.2.3, and the 20.x branch prior to 20.3.21 have an Open Redirect vulnerability in `@angular/ssr` due to an incomplete fix for CVE-2026-27738. While…
CVE-2026-27738MEDIUM2026
The Angular SSR is a server-rise rendering tool for Angular applications. An Open Redirect vulnerability exists in the internal URL processing logic in versions on the 19.x branch prior to 19.2.21, the 20.x branch prior to 20.3.17, and the 21.x branch prior to 21.1.5 and 21.2.0-rc.1. The logic norma…