Medium severity6.1NVD Advisory· Published Aug 3, 2026· Updated Aug 11, 2026
CVE-2026-68945
CVE-2026-68945
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@angular/commonnpm | >= 22.0.0-next.0, < 22.0.2 | 22.0.2 |
@angular/commonnpm | >= 21.0.0-next.0, < 21.2.19 | 21.2.19 |
@angular/commonnpm | >= 20.0.0-next.0, < 20.3.27 | 20.3.27 |
@angular/commonnpm | <= 19.2.25 | — |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/angular/angular/commit/6867f77ec779a0a24f6339ad6c775f444202103cnvdPatchWEB
- github.com/angular/angular/commit/948a8d6831e8920b54663ec79421da95210e0e35nvdPatchWEB
- github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2bnvdPatchWEB
- github.com/angular/angular/commit/a6c7fc5c13e6e494a4c9bd8e773b8d4b2a99b20cnvdPatchWEB
- github.com/advisories/GHSA-jhpw-976m-542jghsaADVISORY
- github.com/angular/angular/security/advisories/GHSA-jhpw-976m-542jnvdVendor AdvisoryWEB
- github.com/angular/angular/pull/68571nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.