WhisperX tag archive

#CVE-2025-66035

This page collects WhisperX intelligence signals tagged #CVE-2025-66035. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-03-29 05:26:56 · GitHub Issues

1. Angular HTTP Client Vulnerability (CVE-2025-66035): XSRF Token Leakage via Protocol-Relative URLs

A critical security flaw in the Angular HTTP client exposes applications to cross-site request forgery (XSRF) attacks. The vulnerability, tracked as CVE-2025-66035 (GHSA-58c5-g7wp-6w37), allows attackers to bypass XSRF protections by exploiting how the client handles protocol-relative URLs. This can lead to the leakage...

The Lab · 2026-04-12 11:22:37 · GitHub Issues

2. Angular HTTP Client Security Flaw: XSRF Token Leakage via Protocol-Relative URLs (CVE-2025-66035)

A critical security vulnerability in the Angular framework's HTTP client has been publicly disclosed, exposing applications to cross-site request forgery (XSRF) attacks. The flaw, tracked as CVE-2025-66035 (GHSA-58c5-g7wp-6w37), resides in how the client handles protocol-relative URLs, potentially allowing attackers to...

The Lab · 2026-05-03 07:54:08 · GitHub Issues

3. Angular HTTP Client XSRF Token Leakage Vulnerability Triggers Urgent Four-Version Security Patch

Google's Angular framework has released emergency security updates addressing a critical cross-site request forgery (XSRF) token leakage flaw in the HttpClient module. Tracked as CVE-2025-66035 (GHSA-58c5-g7wp-6w37), the vulnerability stems from how Angular's HTTP client handles protocol-relative URLs—web addresses tha...