GHSA-gv2q-mqqv-365m

Suggest an improvement
Source
https://github.com/advisories/GHSA-gv2q-mqqv-365m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gv2q-mqqv-365m/GHSA-gv2q-mqqv-365m.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-gv2q-mqqv-365m
Aliases
Published
2026-06-15T16:44:21Z
Modified
2026-07-15T22:15:55Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.7 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
Details

An issue in the @angular/service-worker package compromises the integrity of request-policy enforcement during request reconstruction. When the Angular Service Worker intercepts network requests for matched assets, it reconstructs a new Request object using an internal helper function.

During this reconstruction process, the helper function strips the strict, client-defined request redirect policy configuration (such as redirect: 'error'), falling back to the browser's default 'follow' strategy.

If the target web application makes client-side requests with a strict policy (e.g., expecting a network error instead of automatically following redirects), the service worker will bypass this instruction and automatically follow HTTP 3xx redirects to other destinations. This acts as an unintended proxy/intermediary ("Confused Deputy") and can result in cookie/credential exposure or same-origin session-restricted data leakage if public dynamic routes redirect to sensitive routes.

Impact

Web applications registering the @angular/service-worker package are vulnerable to this redirect-policy bypass if they make safe client-side fetch calls (such as { redirect: 'error' }) to paths matched by a service worker asset group (such as lazy-loaded JavaScript bundles or dynamic public assets) that can return HTTP redirects to authenticated same-origin secure endpoints.

By stripping developer-defined safety boundaries, the service worker allows the browser to transparently query and return data from credentials-guarded resources that should have been blocked at the network barrier.

Attack Preconditions

To successfully exploit this vulnerability, all of the following application states and parameters must concurrently exist:

  1. Active Angular Service Worker: The target application uses @angular/service-worker and has an active registration of ngsw-worker.js inside the client's browser context.
  2. Asset Group Matching: An assetGroups pattern in ngsw-config.json encompasses the target dynamic routing endpoint.
  3. Same-Origin Dynamic Redirection: The server routes a public matched asset route to a service that returns an HTTP 3xx redirect pointing to a sensitive, session-restricted same-origin private route (e.g., /private/account-summary.json).
  4. Established User Session: The victim user currently has an active authentication state, such as valid same-origin session cookies or auth headers stored by the browser.
  5. Client-Side Safe Fetch Call: The application initiates an explicit fetch request to the route with safety parameters: { redirect: 'error' }.

Mitigations & Workarounds

If upgrading the @angular/service-worker package is not immediately feasible, developers should implement the following defensive measures:

  • Avoid Public-to-Private Dynamic Redirection: Refactor the server architecture so that public paths matched by service worker asset groups never issue HTTP 3xx redirects to authenticated same-origin secure endpoints.
  • Strict Cookie Configuration: Apply strict flags to session cookies (SameSite=Strict; Secure; HttpOnly) and consider explicit route isolations (such as subdomains) for credential-guarded private resources.
  • Exclude Secure Endpoints from SW Config: Verify your ngsw-config.json settings and ensure that patterns targeting dynamic, secure endpoints are explicitly excluded from automatic asset groups or caching scopes.

Patches

  • 22.0.0-rc.2
  • 21.2.15
  • 20.3.22
  • 19.2.23
Database specific
{
    "cwe_ids": [
        "CWE-200",
        "CWE-441",
        "CWE-524"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-06-15T16:44:21Z",
    "nvd_published_at": "2026-06-22T18:16:42Z",
    "severity": "MODERATE"
}
References

Affected packages

npm
@angular/service-worker

Package

Name
@angular/service-worker
View open source insights on deps.dev
Purl
pkg:npm/%40angular/service-worker

Affected ranges

Type
SEMVER
Events
Introduced
22.0.0-next.0
Fixed
22.0.0-rc.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gv2q-mqqv-365m/GHSA-gv2q-mqqv-365m.json"
@angular/service-worker

Package

Name
@angular/service-worker
View open source insights on deps.dev
Purl
pkg:npm/%40angular/service-worker

Affected ranges

Type
SEMVER
Events
Introduced
20.0.0-next.0
Fixed
20.3.22

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gv2q-mqqv-365m/GHSA-gv2q-mqqv-365m.json"
@angular/service-worker

Package

Name
@angular/service-worker
View open source insights on deps.dev
Purl
pkg:npm/%40angular/service-worker

Affected ranges

Type
SEMVER
Events
Introduced
19.0.0-next.0
Fixed
19.2.23

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gv2q-mqqv-365m/GHSA-gv2q-mqqv-365m.json"
@angular/service-worker

Package

Name
@angular/service-worker
View open source insights on deps.dev
Purl
pkg:npm/%40angular/service-worker

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
18.2.14

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gv2q-mqqv-365m/GHSA-gv2q-mqqv-365m.json"
@angular/service-worker

Package

Name
@angular/service-worker
View open source insights on deps.dev
Purl
pkg:npm/%40angular/service-worker

Affected ranges

Type
SEMVER
Events
Introduced
21.0.0-next.0
Fixed
21.2.15

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-gv2q-mqqv-365m/GHSA-gv2q-mqqv-365m.json"