CVE-2026-50169Medium▾ SunlitAngular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.2%
0.2% → 0.2%
An issue in the @angular/service-worker package compromises the integrity of request-policy enforcement during request reconstruction. When the Angular Service Worker intercepts network requests for matched assets, it reconstructs a new Request object using an internal helper function.
During this reconstruction process, the helper function strips the strict, client-defined request redirect policy configuration (such as redirect: 'error'), falling back to the browser's default 'follow' strategy.
If the target web application makes client-side requests with a strict policy (e.g., expecting a network error instead of automatically following redirects), the service worker will bypass this instruction and automatically follow HTTP 3xx redirects to other destinations. This acts as an unintended proxy/intermediary ("Confused Deputy") and can result in cookie/credential exposure or same-origin session-restricted data leakage if public dynamic routes redirect to sensitive routes.
Web applications registering the @angular/service-worker package are vulnerable to this redirect-policy bypass if they make safe client-side fetch calls (such as { redirect: 'error' }) to paths matched by a service worker asset group (such as lazy-loaded JavaScript bundles or dynamic public assets) that can return HTTP redirects to authenticated same-origin secure endpoints.
By stripping developer-defined safety boundaries, the service worker allows the browser to transparently query and return data from credentials-guarded resources that should have been blocked at the network barrier.
To successfully exploit this vulnerability, all of the following application states and parameters must concurrently exist:
@angular/service-worker and has an active registration of ngsw-worker.js inside the client's browser context.assetGroups pattern in ngsw-config.json encompasses the target dynamic routing endpoint./private/account-summary.json).{ redirect: 'error' }.If upgrading the @angular/service-worker package is not immediately feasible, developers should implement the following defensive measures:
SameSite=Strict; Secure; HttpOnly) and consider explicit route isolations (such as subdomains) for credential-guarded private resources.ngsw-config.json settings and ensure that patterns targeting dynamic, secure endpoints are explicitly excluded from automatic asset groups or caching scopes.@angular/service-worker >= 22.0.0-next.0, < 22.0.0-rc.2@angular/service-worker >= 20.0.0-next.0, < 20.3.22@angular/service-worker >= 19.0.0-next.0, < 19.2.23@angular/service-worker <= 18.2.14@angular/service-worker >= 21.0.0-next.0, < 21.2.15Upgrade to a patched release:
@angular/service-worker 22.0.0-rc.2@angular/service-worker 20.3.22@angular/service-worker 19.2.23@angular/service-worker 21.2.15Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50184Medium@angular/service-worker: Request Credential & Cache Policy Stripping
CVE-2026-54264High@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
CVE-2026-88059Medium· 4.0Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
CVE-2026-50170High@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
CVE-2021-25122High· 7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning u…
CVE-2022-31746Medium· 6.5Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header