Use of cache containing sensitive information in Angular - CVE-2026-50184

 

Use of cache containing sensitive information in Angular - CVE-2026-50184

Published: September 11, 2026


Vulnerability identifier: #VU148999
CSH Severity: Medium
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-50184
CWE-ID: CWE-524
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper preservation of request security settings in the Angular Service Worker internal request reconstruction helper when intercepting requests for matched assets. A remote attacker can cause requests with explicit credential or cache safety settings to be reconstructed to disclose sensitive information.

Exploitation requires an active service worker registration, a matching asset group, an established user session, and a client-side fetch request with explicit credential or cache safety settings.


Affected software

Angular

How to mitigate CVE-2026-50184

Install security update from vendor's website.

Angular - addressed in versions 19.2.23, 20.3.22, 21.2.15, 22.0.0

External References

Related Security Bulletins