General Information
- Severity: high
- Title: @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache
- Category: vulnerabilities
- Rule: CVE-2026-68945
- Alert hash: aa71457b2bdb1f25917f47bb3ca6d11f
- First seen: 2026-08-10
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.
(This package is used under: @angular/common@21.2.7)
Location
Dependency Details
- Package name: @angular/common
- Installed version: 21.2.7
- Fixed version: 22.0.2, 21.2.19, 20.3.27
- Reachable: True
General Information
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.
(This package is used under: @angular/common@21.2.7)
Location
Dependency Details