Skip to content

Angular 22.2.1 Fixes Two High-Severity Server-Side Rendering Flaws: Who Needs to Update

  Posted on 30 Sep, 2026
  Tech News
Angular 22.2.1 Fixes Two High-Severity Server-Side Rendering Flaws: Who Needs to Update

Angular has released versions 22.2.1, 21.2.25 and 20.3.33 to fix three security flaws in server-side rendering, two of them rated high severity. The Angular team published the advisories on GitHub on September 30 and October 1, 2026. The high-severity flaws let an outside attacker crash the server that renders an Angular site; the third lets a crafted link send visitors to another website.

Only Angular applications that render pages on a Node.js server are exposed to the two crash flaws. An Angular application that runs entirely in the visitor's browser is not affected by them. If you are not sure which kind you have, that is the first question to put to whoever handles your Angular development, because the answer decides whether this is urgent or routine.

What did Angular fix in versions 22.2.1, 21.2.25 and 20.3.33?

The releases fix two denial-of-service flaws in the Angular router and one open redirect in the server rendering package. All three are listed on Angular's security advisories page. None had a CVE number assigned when we checked on October 6, 2026; they are tracked by GitHub advisory ID.

Server crash through unmatched outlet URLs (high)

Advisory GHSA-62vg-58rm-qff7, published September 30, 2026, carries a severity score of 8.2 out of 10. The router did not check whether a special part of a URL, called an auxiliary outlet segment, matched anything the application had configured. A specially built web address made the server repeat the same matching work until it ran out of memory or processor time. The advisory says a single crafted request, or a small number of concurrent ones, can crash the rendering process.

Server crash through oversized query strings (high)

Advisory GHSA-57xq-rjx2-v5xh, published October 1, 2026, is also scored 8.2. A change introduced in Angular 21.2.0 made every link on a server-rendered page hold on to more memory than before. On pages whose links carry the current query string forward, an attacker can send very long query strings and exhaust the server's memory with what the advisory calls modest concurrent request volume.

Open redirect through protocol-relative URLs (moderate)

Advisory GHSA-w739-gvwx-grc3, published September 30, 2026, is scored 5.1. A crafted path could slip past Angular's check and make the server answer with a redirect to an outside domain. The link looks like it points at your site, which is what makes it useful for phishing.

Is my Angular application affected?

Your application is affected if it uses Angular server-side rendering on Node.js and runs a version older than the patched releases. Server-side rendering, or SSR, means the server builds each page before sending it, which helps search visibility and first-load speed. It is common on public marketing sites, online stores and content sites built with Angular.

The outlet advisory states plainly that client-side single-page applications are unaffected and that static prerendering, where pages are generated once at build time, is not vulnerable. Many internal dashboards and admin panels fall into the client-side group.

Each flaw also needs specific conditions. The query-string flaw requires links that use Angular's "merge" or "preserve" query parameter handling and a proxy in front of the site that forwards very long request lines. The outlet flaw requires routes with empty paths or named outlets, which many applications have. The redirect flaw depends on particular route shapes and on a reverse proxy that does not normalize unusual path characters. A developer can check all of this in the code and hosting configuration in a short review.

Which Angular versions contain the fixes?

The fixes are in Angular 22.2.1, 21.2.25 and 20.3.33, according to the three advisories. The details differ slightly by flaw:

  • Angular 22: all three flaws affect versions 22.0.0 up to, but not including, 22.2.1. Update to 22.2.1 or later.
  • Angular 21: the outlet and redirect flaws affect 21.0.0 onward; the query-string flaw affects 21.2.0 onward. Update to 21.2.25 or later.
  • Angular 20: the outlet and redirect flaws apply; the query-string flaw is not listed for this version. Update to 20.3.33 or later.
  • Angular 19 and earlier: the outlet and redirect advisories list versions up to 19.2.25 as affected. These versions are out of support and will not be patched.

These are patch releases within each major version, so moving from 22.1 or 22.2.0 to 22.2.1 should not require the kind of rework a major upgrade does. It still needs a test run before it goes live.

What can an attacker actually do with these flaws?

With the two high-severity flaws, an attacker can take a server-rendered Angular site offline without logging in. Both advisories describe the outcome as an out-of-memory crash of the Node.js rendering process. The advisories describe crashes and downtime; they do not describe data being read or altered.

For a business, the cost is availability: a storefront or lead-generation site that goes down repeatedly, possibly at a time chosen by the attacker. The outlet advisory adds that an application's own guard and resolver code runs over and over during an attack, which can pass extra load on to the backend services behind the site.

The open redirect is a trust problem. Someone can circulate a link that begins with your real domain and ends on a site they control. The advisory notes it requires the victim to click the link.

Are there workarounds if we cannot update immediately?

Yes, the advisories list temporary mitigations, all applied in front of the application and not inside it. They are stopgaps for your developer or hosting provider to apply, not a replacement for the update.

  • Limit URL and query-string length at the reverse proxy or web application firewall. The query-string advisory gives 2,048 bytes as an example of a reasonable limit.
  • Block the unusual URL patterns the advisories describe: paths containing parentheses if the application does not use named outlets, and paths containing sequences such as "/.//" or "/.;/".
  • Avoid "merge" and "preserve" query handling on server-rendered links where explicit parameters will do.

The advisories also mention giving Node.js more memory. That raises the bar for an attack but does not remove the flaw.

What does this mean for Angular 20 and older versions?

Angular 20 received this fix, but its support ends soon, and anything older is already on its own. Angular's release and support page lists long-term support for version 20 ending on November 28, 2026, and states that versions 2 to 19 are no longer supported. An SSR application on Angular 19 is exposed to two of these three flaws with no patch coming.

There is also a pattern worth noticing. Angular's advisory page shows eight advisories with server-side rendering in the title published between August 27 and October 1, 2026. That is not a reason to avoid SSR. It does mean an SSR application needs frequent patching, and a version that still receives fixes.

What should a business do now?

Confirm whether you use SSR, then update. In order:

  1. Ask your developer which Angular version each application runs and whether it uses server-side rendering on Node.js.
  2. If it does, schedule the update to 22.2.1, 21.2.25 or 20.3.33 now, with a test pass before release.
  3. If the update will take more than a few days, have the proxy or firewall mitigations applied in the meantime.
  4. If you are on Angular 19 or older with SSR, plan a major-version upgrade. If you are on Angular 20, plan the move to 21 or 22 before November 28, 2026.
  5. Agree on a regular schedule for applying framework patch releases.

Our web application security checklist for business covers the wider set of controls, such as firewalls and monitoring, that limit the damage when a framework flaw like this appears.

Quick answers

Which Angular versions fix the September 30, 2026 SSR vulnerabilities?

Angular 22.2.1, 21.2.25 and 20.3.33 contain the fixes. Angular 19 and earlier are out of support and will not be patched.

Are Angular apps without server-side rendering affected?

No, not by the two high-severity flaws. Angular's advisory says client-side single-page applications are unaffected and static prerendering is not vulnerable; the flaws apply to server-side rendering on Node.js.

How serious are the Angular SSR vulnerabilities?

Two are rated high, with a severity score of 8.2 out of 10, and allow an unauthenticated attacker to crash the server rendering process. The third is rated moderate, 5.1, and allows an open redirect to an outside site.

Do these Angular flaws expose customer data?

The advisories for the two high-severity flaws describe server crashes and downtime, not data being read or changed. The open redirect can be used in phishing links that appear to point to your domain.

When does Angular 20 support end?

Angular's release page lists long-term support for Angular 20 ending on November 28, 2026. After that date, Angular 20 will no longer receive security patches.

Conclusion

Angular's patch releases 22.2.1, 21.2.25 and 20.3.33 close two high-severity flaws that can crash a server-rendered Angular site and one moderate open redirect. Browser-only Angular applications are not exposed to the crash flaws. If you run Angular with server-side rendering, update to the patched release for your version, use the proxy mitigations if you need a few days, and treat Angular 19 or older as overdue for an upgrade.

Entrant Technologies builds websites, web applications, mobile apps and custom software. If you have no developer available to check your Angular version or apply the update, contact us and we will take a look.

Entrant Technologies
Post written by
Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations.
View all posts by Entrant Technologies →
Latest Blogs
 
If your WordPress site is sending visitors to another website, showing spam pages, or has administrator accounts you did not create, treat it as compromised. Start by writing down what you see and whe ...
on 06 Oct, 2026 Read More
 
To be cited by ChatGPT search and other AI assistants, your pages first have to be reachable by each provider's search crawler, and then they have to state clear, accurate answers in plain text that a ...
on 06 Oct, 2026 Read More
 
A 500 Internal Server Error that appears right after a PHP or hosting upgrade usually means the server is running, but your website's code, a plugin or a theme failed on the new PHP version or server ...
on 06 Oct, 2026 Read More