GHSA-jhpw-976m-542j

Suggest an improvement
Source
https://github.com/advisories/GHSA-jhpw-976m-542j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jhpw-976m-542j/GHSA-jhpw-976m-542j.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-jhpw-976m-542j
Aliases
Downstream
Published
2026-08-03T15:59:13Z
Modified
2026-08-03T16:26:14Z
Severity
  • 8.8 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
Details

Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration.

During SSR, HttpTransferCache previously generated identical key material for distinct request parameters when repeated values were present because repeated values were joined with commas:

new HttpParams().set('role', 'user,admin')
new HttpParams().append('role', 'user').append('role', 'admin')

Both requests previously serialized as role=user,admin, allowing distinct HttpClient requests to produce the same transfer-cache key material.

Impact

In an SSR application, this cache-key ambiguity can make a later security-sensitive HttpClient request receive the response from an earlier semantically different request in the same render. For example, an attacker-influenced scalar-comma request can be cached and then replayed as the response for a trusted repeated-param authorization or data request to the same URL. As a result, Angular's server-rendered output can be based on the wrong backend response because the trusted request is not dispatched. This can lead to:

  • State Poisoning: Using incorrect or attacker-influenced cached responses for subsequent application logic.
  • Cross-Request Response Reuse: Reusing cached responses across requests with semantically different parameters.

Patched Versions

  • 22.0.2
  • 21.2.19
  • 20.3.27

Workarounds

If you cannot upgrade immediately, configure your HttpClient requests to skip transfer caching for sensitive endpoints where repeated parameter keys are used:

this.http.get('/api/resource', {
  transferCache: false
});

Alternatively, disable the HTTP transfer cache globally in your application bootstrap config:

import { provideClientHydration, withNoHttpTransferCache } from '@angular/platform-browser';

export const appConfig = {
  providers: [
    provideClientHydration(
      withNoHttpTransferCache()
    )
  ]
};
Database specific
{
    "cwe_ids":  [
        "CWE-345"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-03T15:59:13Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @angular/common

Package

Name
@angular/common
View open source insights on deps.dev
Purl
pkg:npm/%40angular/common

Affected ranges

Type
SEMVER
Events
Introduced
22.0.0-next.0
Fixed
22.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jhpw-976m-542j/GHSA-jhpw-976m-542j.json"

npm / @angular/common

Package

Name
@angular/common
View open source insights on deps.dev
Purl
pkg:npm/%40angular/common

Affected ranges

Type
SEMVER
Events
Introduced
21.0.0-next.0
Fixed
21.2.19

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jhpw-976m-542j/GHSA-jhpw-976m-542j.json"

npm / @angular/common

Package

Name
@angular/common
View open source insights on deps.dev
Purl
pkg:npm/%40angular/common

Affected ranges

Type
SEMVER
Events
Introduced
20.0.0-next.0
Fixed
20.3.27

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jhpw-976m-542j/GHSA-jhpw-976m-542j.json"

npm / @angular/common

Package

Name
@angular/common
View open source insights on deps.dev
Purl
pkg:npm/%40angular/common

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
19.2.25

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jhpw-976m-542j/GHSA-jhpw-976m-542j.json"