PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-66035 Siemens CVE debrief

CVE-2025-66035 is a credential-leak issue in Angular HttpClient’s XSRF handling. When a request uses a protocol-relative URL beginning with //, Angular can misclassify it as same-origin and automatically attach the X-XSRF-TOKEN header, potentially exposing the token to an attacker-controlled domain. The advisory states the issue is fixed in Angular 19.2.16, 20.3.14, and 21.0.1, and recommends avoiding protocol-relative URLs in HttpClient requests.

Vendor
Siemens
Product
SIDIS Prime
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-10
Original CVE updated
2026-03-12
Advisory published
2026-03-10
Advisory updated
2026-03-12

Who should care

Teams maintaining Angular-based web applications or embedded web clients that use HttpClient and rely on XSRF protection. In the supplied advisory corpus, this CVE is also associated with Siemens/CISA republished material, so organizations consuming the referenced Siemens advisory should review affected deployments and client code paths.

Technical summary

Angular HttpClient decides whether to add XSRF headers by checking whether a request URL begins with a protocol such as http:// or https://. A protocol-relative URL (//) bypasses that expectation and can be treated as same-origin, causing the X-XSRF-TOKEN header to be sent when it should not be. The result is unauthorized disclosure of the XSRF token to the destination domain. The supplied advisory says the issue is patched in Angular 19.2.16, 20.3.14, and 21.0.1 and can be mitigated by avoiding protocol-relative URLs.

Defensive priority

High. The issue affects confidentiality of a security token and can be triggered through application logic without requiring privileges. Even though it is not a code-execution bug, the leakage can weaken CSRF protections and should be remediated promptly in client code and dependency versions.

Recommended defensive actions

  • Upgrade Angular to 19.2.16, 20.3.14, or 21.0.1, or later fixed releases listed by the vendor.
  • Search for HttpClient calls that use protocol-relative URLs beginning with // and replace them.
  • Use relative paths starting with / or fully qualified, trusted absolute URLs for backend requests.
  • Review application code and shared libraries for URL construction patterns that may reintroduce protocol-relative requests.
  • Validate that affected builds no longer send X-XSRF-TOKEN to nontrusted destinations after remediation.

Evidence notes

The supplied source item and CISA advisory metadata are dated 2026-03-10 with a CISA republication on 2026-03-12. The advisory text explicitly describes an Angular HttpClient XSRF token leakage condition involving protocol-relative URLs and lists fixed Angular versions 19.2.16, 20.3.14, and 21.0.1. The source corpus also labels the product as Siemens SIDIS Prime vers:intdot/<4.0.800, which does not match the Angular description; this debrief follows the supplied vulnerability text and flags that mismatch as a source-corpus quality issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-66035 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-66035

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-66035 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66035

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-071-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-485750.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-485750.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-26-071-03.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-071-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.