SB2026082073 - Multiple vulnerabilities in Angular
Published: August 20, 2026 Updated: September 11, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Use of cache containing sensitive information (CVE-ID: CVE-2026-50170)
CWE-ID: CWE-524 - Use of Cache Containing Sensitive Information
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of cache containing sensitive information in HttpTransferCache when processing delegated HTTP requests with withRequestsMadeViaParent() before parent interceptors attach authentication credentials. A remote attacker can request a cached SSR-rendered page containing another user's authenticated response data to disclose sensitive information.
Exploitation requires SSR and hydration to be enabled, a hierarchical HttpClient configuration using withRequestsMadeViaParent(), parent-level injection of authentication credentials, and shared caching of SSR HTML responses across user sessions.
2) Use of cache containing sensitive information (CVE-ID: CVE-2026-50184)
CWE-ID: CWE-524 - Use of Cache Containing Sensitive Information
CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper preservation of request security settings in the Angular Service Worker internal request reconstruction helper when intercepting requests for matched assets. A remote attacker can cause requests with explicit credential or cache safety settings to be reconstructed to disclose sensitive information.
Exploitation requires an active service worker registration, a matching asset group, an established user session, and a client-side fetch request with explicit credential or cache safety settings.
3) Origin validation error (CVE-ID: CVE-2026-50168)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information and inject attacker-controlled content.
The vulnerability exists due to an origin validation error in the Angular SSR HTTP request interceptor (relativeUrlsTransformerInterceptorFn) when handling malformed request URLs. A remote attacker can send a request with a malformed Host header or absolute-form URI to disclose sensitive information and inject attacker-controlled content.
Exploitation requires server-side rendering with raw client URL inputs propagated to the rendering API, relative outbound HTTP requests, and the allowedHosts option enabled.
4) Cross-site scripting (CVE-ID: CVE-2026-52725)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote attacker to execute arbitrary JavaScript in a target user's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the Angular template preparser when compiling user-controlled templates containing custom namespace prefixes. A remote attacker can inject a namespaced script element to execute arbitrary JavaScript in a target user's browser.
Exploitation requires an application to compile user-controlled templates at runtime without separate input sanitization.
5) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-50169)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper preservation of request redirect policies in the @angular/service-worker request reconstruction helper when intercepting network requests for matched assets. A remote attacker can trigger a client-side request to follow a redirect to a sensitive same-origin route to disclose sensitive information.
Exploitation requires an active Angular Service Worker, a matched asset group route that redirects to a session-restricted same-origin route, an active user session, and a client-side fetch configured with redirect: 'error'.
6) Excessive Iteration (CVE-ID: CVE-2026-50171)
CWE-ID: CWE-834 - Excessive Iteration
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive iteration in the formatNumber function when processing a crafted digitsInfo parameter. A remote attacker can supply a digitsInfo value with excessively large fraction digit values to cause a denial of service.
Affected formatting utilities include DecimalPipe, PercentPipe, and CurrencyPipe.
Remediation
Install update from vendor's website.
References
- https://github.com/angular/angular/security/advisories/GHSA-p297-fm68-3q8c
- https://github.com/angular/angular/security/advisories/GHSA-95qp-cmmw-mgqv
- https://github.com/angular/angular/security/advisories/GHSA-xrxm-cp7j-8xf6
- https://github.com/angular/angular/pull/68928
- https://github.com/angular/angular/security/advisories/GHSA-692r-grfm-v8x7
- https://github.com/angular/angular/security/advisories/GHSA-gv2q-mqqv-365m
- https://github.com/angular/angular/pull/67494
- https://github.com/angular/angular/security/advisories/GHSA-p3vc-36g9-x9gr
- https://github.com/angular/angular/pull/68840