Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88059

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authenticated response when Server-Side Rendering (SSR) and hydration use a hierarchical HttpClient configured with withRequestsMadeViaParent. The child TransferCache evaluates an initially anonymous request before delegation, then a parent withInterceptors chain adds an Authorization header, cookie, or API token; although the parent cache skips the authenticated request, the child still stores the private response in TransferState serialized as JSON in the ng-state script. Exploitation requires provideClientHydration, child provideHttpClient delegation through withRequestsMadeViaParent, parent-level credential injection, and an SSR HTML response shared across users by a CDN, reverse proxy, or application cache. A later unauthenticated or unauthorized visitor can receive the cached HTML containing the earlier authenticated user's sensitive response data. Applications can mitigate by attaching credentials at the child, filtering sensitive endpoints with withHttpTransferCacheOptions, disabling transfer caching for sensitive routes, or marking personalized HTML private or no-store. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.1.

A flaw was found in Angular. When Server-Side Rendering (SSR) and hydration are used with a hierarchical HttpClient configured with withRequestsMadeViaParent, the HttpTransferCache can improperly cache authenticated responses. This occurs because a child TransferCache stores private response data in TransferState even when a parent HttpClient chain adds credentials and skips the authenticated request. Consequently, a later unauthenticated or unauthorized visitor could receive cached HTML containing sensitive data from a previously authenticated user, leading to information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1qpid-dispatchOut of support scope
Red Hat Ceph Storage 4rhceph/rhceph-4-dashboard-rhel8Out of support scope
Red Hat Enterprise Linux 10firefoxFix deferred
Red Hat Enterprise Linux 10gjsFix deferred
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 10thunderbirdFix deferred
Red Hat Enterprise Linux 7firefoxFix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 8mozjs60Fix deferred
Red Hat Enterprise Linux 9grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-524
https://bugzilla.redhat.com/show_bug.cgi?id=2531610Angular: Angular: Information Leak via HttpTransferCache Bypass

EPSS

Процентиль: 22%
0.00296
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
5 дней назад

(Angular is a development platform for building mobile and desktop web ...)

CVSS3: 4
nvd
5 дней назад

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authenticated response when Server-Side Rendering (SSR) and hydration use a hierarchical HttpClient configured with withRequestsMadeViaParent. The child TransferCache evaluates an initially anonymous request before delegation, then a parent withInterceptors chain adds an Authorization header, cookie, or API token; although the parent cache skips the authenticated request, the child still stores the private response in TransferState serialized as JSON in the ng-state script. Exploitation requires provideClientHydration, child provideHttpClient delegation through withRequestsMadeViaParent, parent-level credential injection, and an SSR HTML response shared across users by a CDN, reverse proxy, or application cache. A later unauthenticated or unauthorized visitor ca

CVSS3: 4
debian
5 дней назад

Angular is a development platform for building mobile and desktop web ...

CVSS3: 4
github
5 дней назад

Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`

EPSS

Процентиль: 22%
0.00296
Низкий

4 Medium

CVSS3