๐Ÿ” CVE Alert

CVE-2026-68945

UNKNOWN 0.0

Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.

CWE CWE-345
Vendor angular
Product angular
Published Aug 3, 2026
Last Updated Aug 3, 2026
Stay Ahead of the Next One

Get instant alerts for angular angular

Be the first to know when new unknown vulnerabilities affecting angular angular are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

angular / angular
< 20.3.27 >= 21.0.0-next.0, < 21.2.19 >= 22.0.0-next.0, < 22.0.2
@angular / common
< 20.3.27 >= 21.0.0-next.0, < 21.2.19 >= 22.0.0-next.0, < 22.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/angular/angular/security/advisories/GHSA-jhpw-976m-542j github.com: https://github.com/angular/angular/pull/68571 github.com: https://github.com/angular/angular/commit/6867f77ec779a0a24f6339ad6c775f444202103c github.com: https://github.com/angular/angular/commit/948a8d6831e8920b54663ec79421da95210e0e35 github.com: https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b github.com: https://github.com/angular/angular/commit/a6c7fc5c13e6e494a4c9bd8e773b8d4b2a99b20c