Junglewise Threat Intelligence

CVE-2025-59052: Angular Server-Side Rendering race condition in platform injector

CVE-2025-59052 · Severity: medium · CVSS 4 · Published 2025-09-10

Technologies: Google SSR. Vendors: Google, Angular.

Executive brief

Angular's server-side rendering (SSR) feature uses a global data container to store request-specific information. Due to a race condition, concurrent requests can inadvertently access or overwrite each other's data, potentially exposing sensitive information such as authentication tokens or user data in rendered pages or response headers. An attacker with network access could exploit this by sending multiple requests and inspecting responses for leaked data.

Technical details

The vulnerability is a race condition (CWE-362) in Angular's server-side rendering architecture where the global "platform injector" dependency injection container is stored as a module-scoped global variable rather than being isolated per request. When multiple HTTP requests are processed concurrently on the same server, the injector state can be shared or overwritten between requests, allowing request handlers to access data or tokens intended for other requests. The attack vector requires only network access to send concurrent requests to an SSR-enabled Angular application; the attacker passively inspects responses for leaked information. The vulnerability affects standalone applications using bootstrapApplication and any application calling getPlatform() in custom bootstrap logic. Patches have been released for all active Angular versions (18.2.14, 19.2.15, 20.3.0, 21.0.0-next.3), with fixes also available in @angular/ssr and @nguniversal/common.

Affected products

  • Google Angular 16.0.0-next.0 to 18.2.13, 19.0.0-next.0 to 19.2.14, 20.0.0-next.0 to 20.2.x, 21.0.0-next.0 to 21.0.0-next.2
  • Google @angular/platform-server 16.0.0-next.0 to 18.2.13, 19.0.0-next.0 to 19.2.14, 20.0.0-next.0 to 20.2.x, 21.0.0-next.0 to 21.0.0-next.2
  • Google @angular/ssr 17.0.0-next.0 to 18.2.20, 19.0.0-next.0 to 19.2.15, 20.0.0-next.0 to 20.2.x, 21.0.0-next.0 to 21.0.0-next.2
  • Angular @nguniversal/common 16.0.0-next.0 to 16.2.0

Timeline

  • 2025-09-10: disclosed: Advisory published
  • 2025-09-10: patched: Patches released for Angular 18.2.14, 19.2.15, 20.3.0, 21.0.0-next.3 and corresponding @angular/ssr versions

References