Use of cache containing sensitive information in Angular - CVE-2026-50184
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper preservation of request security settings in the Angular Service Worker internal request reconstruction helper when intercepting requests for matched assets. A remote attacker can cause requests with explicit credential or cache safety settings to be reconstructed to disclose sensitive information.
Exploitation requires an active service worker registration, a matching asset group, an established user session, and a client-side fetch request with explicit credential or cache safety settings.