Information disclosure in Angular - CVE-2026-54264
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive credentials and session identifiers.
The vulnerability exists due to improper handling of cross-origin redirects in the Angular Service Worker asset-fetching functionality when fetching assets that are redirected to a different origin. A remote attacker can cause a cross-origin redirect to an untrusted origin to disclose sensitive credentials and session identifiers.
Exploitation requires asset-group requests to include sensitive headers or cookies.