CVE-2026-41423 | Angular up to 19.2.20/20.3.18/21.2.8 URLs server-side request forgery
A vulnerability classified as critical has been found in Angular up to 19.2.20/20.3.18/21.2.8. This affects an unknown function of the component URLs Handler. This manipulation causes server-side request forgery.
This vulnerability is registered as CVE-2026-41423. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.