Skip to content

[SEC:HIGH][FP=aa71457b] @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache #61

Description

@github-actions

General Information

  • Severity: high
  • Title: @angular/common: Angular: Cross-Request Response Reuse and State Poisoning in HttpTransferCache
  • Category: vulnerabilities
  • Rule: CVE-2026-68945
  • Alert hash: aa71457b2bdb1f25917f47bb3ca6d11f
  • First seen: 2026-08-10

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.
(This package is used under: @angular/common@21.2.7)

Location

Dependency Details

  • Package name: @angular/common
  • Installed version: 21.2.7
  • Fixed version: 22.0.2, 21.2.19, 20.3.27
  • Reachable: True

Metadata

Metadata

Labels

scope:securitySecurity, auth, compliancetype:tech-debtMarks task as a tech-debt item

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions