Skip to main content

Use of Cache Containing Sensitive Information

CVE-2026-50170

Severity High
Score 8.2/10

Summary

A vulnerability was discovered in `@angular/common` when Server-Side Rendering (SSR) and hydration are enabled. The `HttpTransferCache` utility optimizes hydration by caching outgoing HTTP requests performed during SSR and transferring the cached state to the client-side application via `TransferState`. Issue has been patched in 22.0.0-rc.2, 20.3.22, 19.2.23, 21.2.15.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-524 - Use of Cache Containing Sensitive Information

The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.

References

Advisory Timeline

  • Published