SecBoard
Zurück zur CVE-Übersicht

CVE-2026-68945

MEDIUM(6.1)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Risk Signal Score15/100 — NIEDRIG
  • CVSS 6.1 — Mittel

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

0.1%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

6.1

Technische Schwere

Beschreibung

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.

Betroffene Produkte

  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*

GitHub Advisories

GHSA-jhpw-976m-542jHIGH

Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning

npm/@angular/common22.0.2
GitHub Advisory

Referenzen