{"id":"GHSA-qxh6-94w6-9r5p","summary":"@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker","details":"An information disclosure vulnerability exists in the `@angular/service-worker` package of the Angular framework. When the Service Worker fetches assets, it preserves metadata (such as headers) from the original request. However, on cross-origin redirects, the Service Worker fails to strip sensitive headers, violating the Fetch redirect algorithm. \n\nThis allows a remote attacker to obtain sensitive credentials (e.g., `Authorization` tokens, `Proxy-Authorization` credentials, or session cookies) by triggering a cross-origin redirect to an untrusted external origin.\n\n### Impact\nIf an application configured with the Angular Service Worker fetches assets with credential headers (such as `Authorization` header), and one of those requests is redirected to a different origin, the Service Worker will forward those headers to the new origin. This exposes critical credentials and session identifiers to unauthorized third-party servers.\n\n### Attack Preconditions\nFor this vulnerability to be exploitable:\n1. **Vulnerable Configuration:** The application must utilize the `@angular/service-worker` package to fetch assets.\n2. **Credentialed Requests:** The application must attach sensitive request headers (like `Authorization`, `Proxy-Authorization`, or rely on cookies) to asset-group requests.\n3. **Redirect Flow:** These requests must encounter a cross-origin redirect to an attacker-controlled or untrusted domain.\n\n### Patched Versions\n* 22.0.1  \n* 21.2.17  \n* 20.3.25\n\n### Credits\nThis vulnerability was discovered and reported by [CodeMender from Google DeepMind](https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/).","aliases":["CVE-2026-54264"],"modified":"2026-07-15T22:15:56.655790564Z","published":"2026-06-15T17:25:55Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-15T17:25:55Z","nvd_published_at":"2026-06-22T16:16:39Z","cwe_ids":["CWE-200","CWE-359"]},"references":[{"type":"WEB","url":"https://github.com/angular/angular/security/advisories/GHSA-qxh6-94w6-9r5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54264"},{"type":"WEB","url":"https://github.com/angular/angular/pull/69029"},{"type":"WEB","url":"https://github.com/angular/angular/commit/47d68dcb26266316647133ab6385e77fc3e5ae08"},{"type":"PACKAGE","url":"https://github.com/angular/angular"}],"affected":[{"package":{"name":"@angular/service-worker","ecosystem":"npm","purl":"pkg:npm/%40angular/service-worker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"22.0.0-next.0"},{"fixed":"22.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-qxh6-94w6-9r5p/GHSA-qxh6-94w6-9r5p.json"}},{"package":{"name":"@angular/service-worker","ecosystem":"npm","purl":"pkg:npm/%40angular/service-worker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.0.0-next.0"},{"fixed":"21.2.17"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-qxh6-94w6-9r5p/GHSA-qxh6-94w6-9r5p.json"}},{"package":{"name":"@angular/service-worker","ecosystem":"npm","purl":"pkg:npm/%40angular/service-worker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0-next.0"},{"fixed":"20.3.25"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-qxh6-94w6-9r5p/GHSA-qxh6-94w6-9r5p.json"}},{"package":{"name":"@angular/service-worker","ecosystem":"npm","purl":"pkg:npm/%40angular/service-worker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"19.2.25"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-qxh6-94w6-9r5p/GHSA-qxh6-94w6-9r5p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"}]}