{"id":"CVE-2026-54264","aliases":["GHSA-qxh6-94w6-9r5p"],"url":"https://o3.security/vulnerability/CVE-2026-54264","summary":"Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker","details":"Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vulnerability exists in the @angular/service-worker package of the Angular framework. When the Service Worker fetches assets, it preserves metadata (such as headers) from the original request. However, on cross-origin redirects, the Service Worker fails to strip sensitive headers, violating the Fetch redirect algorithm. This allows a remote attacker to obtain sensitive credentials (e.g., Authorization tokens, Proxy-Authorization credentials, or session cookies) by triggering a cross-origin redirect to an untrusted external origin. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.","published":"2026-06-22T15:32:48.163Z","modified":"2026-07-15T02:20:59.974976746Z","cvss":null,"epss":{"score":0.00235,"percentile":0.14483,"asOf":"2026-08-10"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@angular/service-worker","fixedVersion":"22.0.1"},{"ecosystem":"npm","name":"@angular/service-worker","fixedVersion":"21.2.17"},{"ecosystem":"npm","name":"@angular/service-worker","fixedVersion":"20.3.25"},{"ecosystem":"npm","name":"@angular/service-worker","fixedVersion":null}],"fix":{"url":"https://github.com/angular/angular/commit/47d68dcb26266316647133ab6385e77fc3e5ae08","label":"angular/angular@47d68dc"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54264.json"},{"type":"ADVISORY","url":"https://github.com/angular/angular/security/advisories/GHSA-qxh6-94w6-9r5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54264"},{"type":"FIX","url":"https://github.com/angular/angular/commit/47d68dcb26266316647133ab6385e77fc3e5ae08"},{"type":"FIX","url":"https://github.com/angular/angular/pull/69029"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T02:20:59.974976746Z"}}