CVE-2026-54264
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular framework. When the Service Worker fetches assets, it preserves metadata (such as headers) from the original request. However, on cross-origin redirects, the Service Worker fails to strip sensitive headers, violating the Fetch redirect algorithm. This allows a remote attacker to obtain sensitive credentials (e.g., Authorization tokens, Proxy-Authorization credentials, or session cookies) by triggering a cross-origin redirect to an untrusted external origin. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
- EPSS probability
- 0.39%
- CWE
- CWE-200, CWE-359
- Published
- 2026-06-22
- Last modified
- 2026-06-23
Affected products
- angular angular
- angular angular
- angular angular
- angular angular
Weakness type
Related vulnerabilities
- CVE-2026-88893 — OpenPanel Unauthenticated Share Lookup Information Disclosure
- CVE-2026-88876 — AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD
- CVE-2026-88874 — AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass
- CVE-2026-0305 — Prisma Access Agent: Information Disclosure Vulnerability on Linux
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets
- CVE-2026-87820 — CyberPanel 2.4.3 through 2.4.5 Information Disclosure via AI Scanner
- CVE-2026-87810 — Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock