CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-jhpw-976m-542j: Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning

highCVE-2026-68945
Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration. During SSR, HttpTransferCache previously generated identical key material for distinct request parameters when repeated values were present because repeated values were joined with commas: new HttpParams().set('role', 'user,admin') new HttpParams().append('role', 'user').append('role', 'admin') Both requests previously serialized as role=user,admin, allowing distinct HttpClient requests to produce the same transfer-cache key material. Impact In an SSR application, this cache-key ambiguity can make a later security-sensitive HttpClient request receive the response from an earlier semantically different request in the same render. For example, an attacker-influenced scalar-comma request can be cached and then replayed as the response for a trusted repeated-param authorization or data request to the same URL. As a result, Angular's server-rendered output can be based on the wrong backend response because the trusted request is not dispatched. This can lead to: - State Poisoning: Using incorrect or attacker-influenced cached responses for subsequent application logic. - Cross-Request Response Reuse: Reusing cached responses across requests with semantically different parameters. Patched Versions - 22.0.2 - 21.2.19 - 20.3.27 Workarounds If you cannot upgrade immediately, configure your HttpClient requests to skip transfer caching for sensitive endpoints where repeated parameter keys are used: this.http.get('/api/resource', { transferCache: false }); Alternatively, disable the HTTP transfer cache globally in your application bootstrap config: import { provideClientHydration, withNoHttpTransferCache } from '@angular/platform-browser'; export const appConfig = { providers: [ provideClientHydration( withNoHttpTransferCache() ) ] };

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high
Published
2026-08-03
Last updated
2026-08-03
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-jhpw-976m-542j

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-68945coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from GitHub Security Advisories