Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-66035

27
FAUCET Score

CVE-2025-66035 describes a Cross-Site Request Forgery (XSRF) token leakage vulnerability in Angular versions prior to 19.2.16, 20.3.14, and 21.0.1. This flaw allows an attacker to obtain the XSRF token due to Angular's HttpClient incorrectly treating protocol-relative URLs (e.g., //example.com) as same-origin, leading to the token being sent to attacker-controlled domains. The vulnerability has a CVSSv4 score of 7.7 (High), indicating a network-based attack with low complexity and a high impact on confidentiality, as it enables unauthorized disclosure of sensitive credentials. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
AngularAngular
< 19.2.16, >= 20.0.0-next.0, < 20.3.14, >= 21.0.0-next.0, < 21.0.1CNA affected

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
HIGH
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.65%
Probability of exploitation in next 30 days
EPSS Percentile
47.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0065 is in the 24th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (30)

npmpatch availablevia ghsa
Product: @angular/commonFixed in: 21.0.1
npmpatch availablevia ghsa
Product: @angular/commonFixed in: 20.3.14
npmpatch availablevia ghsa
Product: @angular/commonFixed in: 19.2.16
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 6Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 5Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: intel-cmt-cat
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: intel-cmt-cat
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: intel-cmt-cat
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-hawtio-online
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-project
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.syndesis-syndesis-parent
redhatend of lifevia redhat_api
Product: Red Hat Single Sign-On 7Fixed in: org.keycloak-keycloak-parent
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: thunderbird
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: firefox
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: gjs
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: thunderbird
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: firefox
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: firefox
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mozjs60
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/kibana6-rhel8
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: firefox
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: gjs
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: thunderbird
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.apicurio-apicurito
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-hawtio-integration

Vendor Advisories (2)

npmGHSA-58c5-g7wp-6w37high

Angular is Vulnerable to XSRF Token Leakage via Protocol-Relative URLs in Angular HTTP Client

Nov 26, 2025
redhatCVE-2025-66035Moderate

angular: Angular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLs

Nov 26, 2025

References

cert-portal.siemens.com / productcert/html/ssa-253495.html
cert-portal.siemens.com / productcert/html/ssa-485750.html
github.com / angular/angular/commit/0276479e7d0e280e0f8d26fa567d3b7aa97a516f
github.com / angular/angular/commit/05fe6686a97fa0bcd3cf157805b3612033f975bc
github.com / angular/angular/commit/3240d856d942727372a705252f7c8c115394a41e
github.com / angular/angular/releases/tag/19.2.16
github.com / angular/angular/releases/tag/20.3.14
github.com / angular/angular/releases/tag/21.0.1
github.com / angular/angular/security/advisories/GHSA-58c5-g7wp-6w37