Modification of assumed-immutable data in Angular - CVE-2026-54267
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to poison HTTP Transfer Cache responses.
The vulnerability exists due to improper control of assumed-immutable data in the Angular client hydration state-container lookup when processing attacker-controlled element IDs before the genuine state script is parsed. A remote attacker can inject a clobbered ng-state element containing forged JSON to poison HTTP Transfer Cache responses.
User interaction is required.