Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-50184 Details

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in the @angular/service-worker package compromises the integrity of request-policy enforcement during request reconstruction. When the Angular Service Worker intercepts network requests for matched assets, it reconstructs a new Request object using an internal helper function. During this reconstruction process, the helper function strips explicit client-defined safety parameters: the credentials configuration (such as credentials: 'omit') and the HTTP cache mode configuration (such as cache: 'no-store'). These are reverted back to standard browser-default parameters (credentials: 'same-origin' and default HTTP cache properties). This causes the browser to include active credentials (such as cookies or Authorization headers) on outbound requests where the client-side developer explicitly instructed they should be omitted, leading to potential session leaks. Additionally, it causes private or non-cacheable resources to be cached by the service worker's engine, making private page states accessible or persistent inside the client's local cache post-logout. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-200Exposure of Sensitive Information to an Unauthorized Actor[email protected]
CWE-524Use of Cache Containing Sensitive Information[email protected]

Affected Products

ProductVersions
angular angular
<= 18.2.14
>= 19.0.0, < 19.2.23
>= 20.0.0, < 20.3.22
>= 21.0.0, < 21.2.15
22.0.0 next0

CPE

  • cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next0:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next1:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next10:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next11:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next12:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next2:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next3:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next4:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next5:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next6:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next7:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next8:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:next9:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:rc0:*:*:*:node.js:*:*
  • cpe:2.3:a:angular:angular:22.0.0:rc1:*:*:*:node.js:*:*

Remediation

  • No remediation found in references.

Change History

4 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-50184
NVD Published Date:
Jun 22, 2026
NVD Last Modified:
Jul 9, 2026
Source:
[email protected]
CVE-2026-50184 Details - Not Deferred