CVE-2026-50169: Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities

Published Jun 15, 2026
·
Updated

An issue in the @angular/service-worker package compromises the integrity of request-policy enforcement during request reconstruction. When the Angular Service Worker intercepts network requests for matched assets, it reconstructs a new Request object using an internal helper function.

During this reconstruction process, the helper function strips the strict, client-defined request redirect policy configuration (such as redirect: 'error'), falling back to the browser's default 'follow' strategy.

If the target web application makes client-side requests with a strict policy (e.g., expecting a network error instead of automatically following redirects), the service worker will bypass this instruction and automatically follow HTTP 3xx redirects to other destinations. This acts as an unintended proxy/intermediary ("Confused Deputy") and can result in cookie/credential exposure or same-origin session-restricted data leakage if public dynamic routes redirect to sensitive routes.

Impact Web applications registering the @angular/service-worker package are vulnerable to this redirect-policy bypass if they make safe client-side fetch calls (such as { redirect: 'error' }) to paths matched by a service worker asset group (such as lazy-loaded JavaScript bundles or dynamic public assets) that can return HTTP redirects to authenticated same-origin secure endpoints.

By stripping developer-defined safety boundaries, the service worker allows the browser to transparently query and return data from credentials-guarded resources that should have been blocked at the network barrier.

Attack Preconditions To successfully exploit this vulnerability, all of the following application states and parameters must concurrently exist: 1. Active Angular Service Worker: The target application uses @angular/service-worker and has an active registration of ngsw-worker.js inside the client's browser context. 2. Asset Group Matching: An assetGroups pattern in ngsw-config.json encompasses the target dynamic routing endpoint. 3. Same-Origin Dynamic Redirection: The server routes a public matched asset route to a service that returns an HTTP 3xx redirect pointing to a sensitive, session-restricted same-origin private route (e.g., /private/account-summary.json). 4. Established User Session: The victim user currently has an active authentication state, such as valid same-origin session cookies or auth headers stored by the browser. 5. Client-Side Safe Fetch Call: The application initiates an explicit fetch request to the route with safety parameters: { redirect: 'error' }.

Mitigations & Workarounds If upgrading the @angular/service-worker package is not immediately feasible, developers should implement the following defensive measures: Avoid Public-to-Private Dynamic Redirection: Refactor the server architecture so that public paths matched by service worker asset groups never issue HTTP 3xx redirects to authenticated same-origin secure endpoints. Strict Cookie Configuration: Apply strict flags to session cookies (SameSite=Strict; Secure; HttpOnly) and consider explicit route isolations (such as subdomains) for credential-guarded private resources. Exclude Secure Endpoints from SW Config: Verify your ngsw-config.json settings and ensure that patterns targeting dynamic, secure endpoints are explicitly excluded from automatic asset groups or caching scopes.

Patches - 22.0.0-rc.2 - 21.2.15 - 20.3.22 - 19.2.23

Other sources

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15 20.3.22, and 19.2.23, an issue in the @angular/service-worker package compromises the integrity of request-policy enforcement during request reconstruction. When the Angular Service Worker intercepts network requests for matched assets, it reconstructs a new Request object using an internal helper function. During this reconstruction process, the helper function strips the strict, client-defined request redirect policy configuration (such as redirect: 'error'), falling back to the browser's default 'follow' strategy. If the target web application makes client-side requests with a strict policy (e.g., expecting a network error instead of automatically following redirects), the service worker will bypass this instruction and automatically follow HTTP 3xx redirects to other destinations. This acts as an unintended proxy/intermediary ("Confused Deputy") and can result in cookie/credential exposure or same-origin session-restricted data leakage if public dynamic routes redirect to sensitive routes. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

MITRE

Affected Software

24 affected componentsFixes available
npm/@angular/service-worker>=21.0.0-next.0<21.2.15
21.2.15
npm/@angular/service-worker<=18.2.14
npm/@angular/service-worker>=19.0.0-next.0<19.2.23
19.2.23
npm/@angular/service-worker>=20.0.0-next.0<20.3.22
20.3.22
npm/@angular/service-worker>=22.0.0-next.0<22.0.0-rc.2
22.0.0-rc.2
angular Angular Node.js<=18.2.14
angular Angular Node.js>=19.0.0<19.2.23
angular Angular Node.js>=20.0.0<20.3.22
angular Angular Node.js>=21.0.0<21.2.15
angular Angular Node.js=22.0.0-next0
angular Angular Node.js=22.0.0-next1
angular Angular Node.js=22.0.0-next10
angular Angular Node.js=22.0.0-next11
angular Angular Node.js=22.0.0-next12
angular Angular Node.js=22.0.0-next2
angular Angular Node.js=22.0.0-next3
angular Angular Node.js=22.0.0-next4
angular Angular Node.js=22.0.0-next5
angular Angular Node.js=22.0.0-next6
angular Angular Node.js=22.0.0-next7
angular Angular Node.js=22.0.0-next8
angular Angular Node.js=22.0.0-next9
angular Angular Node.js=22.0.0-rc0
angular Angular Node.js=22.0.0-rc1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@angular/service-worker to a version that resolves this vulnerability.

    Fixed in 21.2.15
  2. Upgrade

    Upgrade npm/@angular/service-worker to a version that resolves this vulnerability.

    Fixed in 19.2.23
  3. Upgrade

    Upgrade npm/@angular/service-worker to a version that resolves this vulnerability.

    Fixed in 20.3.22
  4. Upgrade

    Upgrade npm/@angular/service-worker to a version that resolves this vulnerability.

    Fixed in 22.0.0-rc.2
  5. Upgrade

    Upgrade @angular/service-worker to a version that resolves this vulnerability.

    Fixed in 22.0.0-rc.2
  6. Upgrade

    Upgrade @angular/service-worker to a version that resolves this vulnerability.

    Fixed in 21.2.15
  7. Upgrade

    Upgrade @angular/service-worker to a version that resolves this vulnerability.

    Fixed in 20.3.22
  8. Upgrade

    Upgrade @angular/service-worker to a version that resolves this vulnerability.

    Fixed in 19.2.23
  9. Configuration

    In ngsw-config.json, verify `assetGroups` settings and explicitly exclude patterns that target dynamic, secure endpoints from automatic asset groups or caching scopes.

    Angular service worker (ngsw-config.json) assetGroups patterns / caching scopes = Exclude secure endpoints from automatic asset groups or caching scopes (ensure patterns targeting dynamic, secure endpoints are explicitly excluded)
  10. Configuration

    Apply strict flags to session cookies: set `SameSite=Strict; Secure; HttpOnly` for session cookies.

    Session cookie configuration SameSite = Strict
  11. Compensating control

    Refactor server architecture so public paths matched by service worker `assetGroups` never issue HTTP 3xx redirects to authenticated same-origin secure endpoints (e.g., avoid redirecting public matched assets to private credential-guarded routes).

Event History

Jun 15, 2026
Advisory Published
via GitHub·04:44 PM
Data Sourced
via GitHub·04:44 PM
DescriptionWeaknessAffected Software
Jun 22, 2026
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-50169?

The severity of CVE-2026-50169 is rated at 37, indicating a significant vulnerability.

2

How do I fix CVE-2026-50169?

To fix CVE-2026-50169, update the `@angular/service-worker` package to the latest version as recommended in the security advisory.

3

What are the potential impacts of CVE-2026-50169?

CVE-2026-50169 may lead to potential information leakage due to compromised request-policy enforcement.

4

Is CVE-2026-50169 a widespread issue?

CVE-2026-50169 affects users of the `@angular/service-worker` package, particularly those utilizing Angular applications.

5

When was CVE-2026-50169 published?

CVE-2026-50169 was published on June 15, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203