CVE-2026-68945

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-08-03 17:16

Updated : 2026-08-11 18:13


NVD link : CVE-2026-68945

Mitre link : CVE-2026-68945

CVE.ORG link : CVE-2026-68945


JSON object : View

Products Affected

angular

  • angular
CWE
CWE-345

Insufficient Verification of Data Authenticity