HttpTransferCache Vulnerability in Angular Affects Multiple Versions
CVE-2026-68945

8.8HIGH

Key Information:

Vendor

Angular

Vendor
CVE Published:
3 August 2026

What is CVE-2026-68945?

Angular, a leading development platform for web applications, features a vulnerability in its HttpTransferCache. This issue allows repeated request parameters to be comma-joined, leading semantically distinct HttpClient requests to share the same transfer-cache key. Consequently, a wrong backend response may be mistakenly reused. Developers are advised to upgrade to versions 20.3.27, 21.2.19, or 22.0.2 to remediate this issue.

Affected Version(s)

angular < 20.3.27 < 20.3.27

angular >= 21.0.0-next.0, < 21.2.19 < 21.0.0-next.0, 21.2.19

angular >= 22.0.0-next.0, < 22.0.2 < 22.0.0-next.0, 22.0.2

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.