Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs
Published Nov 26, 2025
7.7
HIGHCVSS 4.0
EPSS 0.66%
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF token leakage via protocol-relative URLs in angular HTTP clients. The vulnerability is a Credential Leak by App Logic that leads to the unauthorized disclosure of the Cross-Site Request Forgery (XSRF) token to an attacker-controlled domain. Angular's HttpClient has a built-in XSRF protection mechanism that works by checking if a request URL starts with a protocol (http:// or https://) to determine if it is cross-origin. If the URL starts with protocol-relative URL (//), it is incorrectly treated as a same-origin request, and the XSRF token is automatically added to the X-XSRF-TOKEN header. This issue has been patched in versions 19.2.16, 20.3.14, and 21.0.1. A workaround for this issue involves avoiding using protocol-relative URLs (URLs starting with //) in HttpClient requests. All backend communication URLs should be hardcoded as relative paths (starting with a single /) or fully qualified, trusted absolute URLs.
Affected products
-
- Version < 19.2.16StatusaffectedConstraints-
- Version >= 20.0.0-next.0, < 20.3.14StatusaffectedConstraints-
- Version >= 21.0.0-next.0, < 21.0.1StatusaffectedConstraints-
- Version
No data.
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/volsync-operator-bundle
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/volsync-rhel9
Not affected
Red Hat Ceph Storage 4
ceph
Affected
Red Hat Ceph Storage 5
ceph
Affected
Red Hat Ceph Storage 6
ceph
Affected
Red Hat Ceph Storage 7
ceph
Affected
Red Hat Ceph Storage 8
ceph
Affected
Red Hat Enterprise Linux 10
ceph
Affected
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
gjs
Will not fix
Red Hat Enterprise Linux 10
grafana
Not affected
Red Hat Enterprise Linux 10
intel-cmt-cat
Affected
Red Hat Enterprise Linux 10
thunderbird
Not affected
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 8
dotnet5.0-build-reference-packages
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 8
intel-cmt-cat
Affected
Red Hat Enterprise Linux 8
mozjs60
Will not fix
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
ceph
Affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
gjs
Will not fix
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Enterprise Linux 9
intel-cmt-cat
Affected
Red Hat Enterprise Linux 9
polkit
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat Fuse 7
io.apicurio-apicurito
Will not fix
Red Hat Fuse 7
io.hawt-hawtio-integration
Will not fix
Red Hat Fuse 7
io.hawt-hawtio-online
Will not fix
Red Hat Fuse 7
io.hawt-project
Will not fix
Red Hat Fuse 7
io.syndesis-syndesis-parent
Will not fix
Red Hat JBoss Enterprise Application Platform 7
io.hawt-project
Not affected
Red Hat JBoss Enterprise Application Platform 8
io.hawt-project
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
io.hawt-project
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-kf-notebook-controller-rhel8
Not affected
Red Hat OpenShift AI (RHOAI)
rhoai/odh-notebook-controller-rhel8
Not affected
Red Hat OpenStack Platform 16.2
qpid-dispatch
Not affected
Red Hat Quay 3
quay/quay-rhel8
Not affected
Red Hat Single Sign-On 7
org.keycloak-keycloak-parent
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Will not fix | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-operator-bundle | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Not affected | n/a |
| Red Hat Ceph Storage 4 | ceph | Affected | n/a |
| Red Hat Ceph Storage 5 | ceph | Affected | n/a |
| Red Hat Ceph Storage 6 | ceph | Affected | n/a |
| Red Hat Ceph Storage 7 | ceph | Affected | n/a |
| Red Hat Ceph Storage 8 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 10 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | gjs | Will not fix | n/a |
| Red Hat Enterprise Linux 10 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 10 | intel-cmt-cat | Affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | dotnet5.0-build-reference-packages | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 8 | intel-cmt-cat | Affected | n/a |
| Red Hat Enterprise Linux 8 | mozjs60 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | ceph | Affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | gjs | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | intel-cmt-cat | Affected | n/a |
| Red Hat Enterprise Linux 9 | polkit | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat Fuse 7 | io.apicurio-apicurito | Will not fix | n/a |
| Red Hat Fuse 7 | io.hawt-hawtio-integration | Will not fix | n/a |
| Red Hat Fuse 7 | io.hawt-hawtio-online | Will not fix | n/a |
| Red Hat Fuse 7 | io.hawt-project | Will not fix | n/a |
| Red Hat Fuse 7 | io.syndesis-syndesis-parent | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | io.hawt-project | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | io.hawt-project | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | io.hawt-project | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-kf-notebook-controller-rhel8 | Not affected | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-notebook-controller-rhel8 | Not affected | n/a |
| Red Hat OpenStack Platform 16.2 | qpid-dispatch | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Not affected | n/a |
| Red Hat Single Sign-On 7 | org.keycloak-keycloak-parent | Will not fix | n/a |
@angular/common
npm
Introduced 21.0.0-next.0 Fixed 21.0.1@angular/common
npm
Introduced 20.0.0-next.0 Fixed 20.3.14@angular/common
npm
Introduced 0 Fixed 19.2.16
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @angular/common | 21.0.0-next.0 | 21.0.1 |
| npm | @angular/common | 20.0.0-next.0 | 20.3.14 |
| npm | @angular/common | 0 | 19.2.16 |
Remediation
Red Hat mitigation
By using protocol-relative URLs (URLs starting with //) in HttpClient requests and/or Disabling XSRF token attachment for non-same-origin requests using custom Angular interceptors, this vulnerability can be mitigated.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Nov 28, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.66% (0.00659) | 49.70th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.60% (0.00601) | 43.88th | v5 (v2026.06.15) |
| Nov 27, 2025 | 0.05% (0.00050) | 15.51th | v4 (v2025.03.14) |
References (14)
- https://access.redhat.com/security/cve/CVE-2025-66035 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2417389 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://cert-portal.siemens.com/productcert/html/ssa-485750.html
- https://github.com/advisories/GHSA-58c5-g7wp-6w37 Advisory
- https://github.com/angular/angular/commit/0276479e7d0e280e0f8d26fa567d3b7aa97a516f x_refsource_MISC
- https://github.com/angular/angular/commit/05fe6686a97fa0bcd3cf157805b3612033f975bc x_refsource_MISC
- https://github.com/angular/angular/commit/3240d856d942727372a705252f7c8c115394a41e x_refsource_MISC
- https://github.com/angular/angular/releases/tag/19.2.16 x_refsource_MISC
- https://github.com/angular/angular/releases/tag/20.3.14 x_refsource_MISC
- https://github.com/angular/angular/releases/tag/21.0.1 x_refsource_MISC
- https://github.com/angular/angular/security/advisories/GHSA-58c5-g7wp-6w37 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2025-66035
- https://www.cve.org/CVERecord?id=CVE-2025-66035
Change history (0)
No recorded changes yet.