HttpTransferCache Vulnerability in Angular Affects Multiple Versions
CVE-2026-68945
8.8HIGH
What is CVE-2026-68945?
Angular, a leading development platform for web applications, features a vulnerability in its HttpTransferCache. This issue allows repeated request parameters to be comma-joined, leading semantically distinct HttpClient requests to share the same transfer-cache key. Consequently, a wrong backend response may be mistakenly reused. Developers are advised to upgrade to versions 20.3.27, 21.2.19, or 22.0.2 to remediate this issue.
Affected Version(s)
angular < 20.3.27 < 20.3.27
angular >= 21.0.0-next.0, < 21.2.19 < 21.0.0-next.0, 21.2.19
angular >= 22.0.0-next.0, < 22.0.2 < 22.0.0-next.0, 22.0.2
