PT-2026-49580 · Google · Angular

·

CVE-2026-54264

·

Published

2026-06-15

·

Updated

2026-06-22

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Angular versions prior to 22.0.1 Angular versions prior to 21.2.17 Angular versions prior to 20.3.25
Description An information disclosure issue exists in the @angular/service-worker package. When the Service Worker fetches assets, it preserves metadata from the original request. During cross-origin redirects, the Service Worker fails to strip sensitive headers, which violates the Fetch redirect algorithm. This allows a remote attacker to obtain sensitive credentials, such as Authorization tokens, Proxy-Authorization credentials, or session cookies, by triggering a cross-origin redirect to an untrusted external origin.
Recommendations Update to version 22.0.1 Update to version 21.2.17 Update to version 20.3.25

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54264
GHSA-QXH6-94W6-9R5P

Affected Products

Angular