VYPR
Medium severity6.1GHSA Advisory· Published Jun 22, 2026· Updated Jul 9, 2026

CVE-2026-54264

CVE-2026-54264

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular framework. When the Service Worker fetches assets, it preserves metadata (such as headers) from the original request. However, on cross-origin redirects, the Service Worker fails to strip sensitive headers, violating the Fetch redirect algorithm. This allows a remote attacker to obtain sensitive credentials (e.g., Authorization tokens, Proxy-Authorization credentials, or session cookies) by triggering a cross-origin redirect to an untrusted external origin. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@angular/service-workernpm
>= 22.0.0-next.0, < 22.0.122.0.1
@angular/service-workernpm
>= 21.0.0-next.0, < 21.2.1721.2.17
@angular/service-workernpm
>= 20.0.0-next.0, < 20.3.2520.3.25
@angular/service-workernpm
<= 19.2.25

Affected products

2
  • Angular/AngularGHSA2 versions
    <= 19.2.25+ 1 more
    • (no CPE)range: <= 19.2.25
    • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*range: <=19.2.25

Patches

Vulnerability mechanics

References

5

News mentions

1