CVE-2026-68945: Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.
Other sources
Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration.
During SSR, HttpTransferCache previously generated identical key material for distinct request parameters when repeated values were present because repeated values were joined with commas:
ts new HttpParams().set('role', 'user,admin') new HttpParams().append('role', 'user').append('role', 'admin')
Both requests previously serialized as role=user,admin, allowing distinct HttpClient requests to produce the same transfer-cache key material.
Impact
In an SSR application, this cache-key ambiguity can make a later security-sensitive HttpClient request receive the response from an earlier semantically different request in the same render. For example, an attacker-influenced scalar-comma request can be cached and then replayed as the response for a trusted repeated-param authorization or data request to the same URL. As a result, Angular's server-rendered output can be based on the wrong backend response because the trusted request is not dispatched. This can lead to:
- State Poisoning: Using incorrect or attacker-influenced cached responses for subsequent application logic. - Cross-Request Response Reuse: Reusing cached responses across requests with semantically different parameters.
Patched Versions
- 22.0.2 - 21.2.19 - 20.3.27
Workarounds
If you cannot upgrade immediately, configure your HttpClient requests to skip transfer caching for sensitive endpoints where repeated parameter keys are used:
ts this.http.get('/api/resource', { transferCache: false });
Alternatively, disable the HTTP transfer cache globally in your application bootstrap config:
ts import { provideClientHydration, withNoHttpTransferCache } from '@angular/platform-browser';
export const appConfig = { providers: [ provideClientHydration( withNoHttpTransferCache() ) ] };
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@angular/commonto a version that resolves this vulnerability.Fixed in 20.3.27 - Upgrade
Upgrade
npm/@angular/commonto a version that resolves this vulnerability.Fixed in 21.2.19 - Upgrade
Upgrade
npm/@angular/commonto a version that resolves this vulnerability.Fixed in 22.0.2 - Upgrade
Upgrade
Angular HttpTransferCache (SSR)to a version that resolves this vulnerability.Fixed in 20.3.27 - Upgrade
Upgrade
Angular HttpTransferCache (SSR)to a version that resolves this vulnerability.Fixed in 21.2.19 - Upgrade
Upgrade
Angular HttpTransferCache (SSR)to a version that resolves this vulnerability.Fixed in 22.0.2 - Configuration
For security-sensitive HttpClient calls in SSR where repeated parameter keys are used, set the request option `transferCache: false` (e.g., `this.http.get('/api/resource', { transferCache: false })`).
Angular HttpClient (SSR hydration transfer cache) transferCache = false - Configuration
If you cannot upgrade immediately, disable transfer caching by configuring `provideClientHydration(withNoHttpTransferCache())` in your SSR application bootstrap/providers.
Angular HttpTransferCache (SSR) withNoHttpTransferCache = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68945?
CVE-2026-68945 has a high severity rating of 8.8 per the CVSS scoring system.
How do I fix CVE-2026-68945?
To fix CVE-2026-68945, upgrade to Angular versions 20.3.27, 21.2.19, or 22.0.2 or later.
What type of vulnerability is CVE-2026-68945?
CVE-2026-68945 is a cross-request response reuse vulnerability caused by cache-key ambiguity in HttpTransferCache.
What software is affected by CVE-2026-68945?
CVE-2026-68945 affects the npm package @angular/common.
When was CVE-2026-68945 published?
CVE-2026-68945 was published on August 3, 2026.