CVE-2026-50170
CVE-2026-50170 is a high-severity vulnerability in Angular with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-524.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v4: 8.2
- EPSS exploit prediction: 0% (19th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-38292
- Weakness: CWE-524
- Affected product: Angular
- Published:
- Last modified:
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a vulnerability was discovered in @angular/common when Server-Side Rendering (SSR) and hydration are enabled. The HttpTransferCache utility optimizes hydration by caching outgoing HTTP requests performed during SSR and transferring the cached state to the client-side application via TransferState. However, the caching mechanism fails to inspect the withCredentials flag or the Cookie header of outgoing requests. As a result, credentialed, user-specific responses may be cached by default in the shared TransferState payload. When these responses are serialized into the HTML, any caching layer (such as a CDN, reverse proxy, or shared server cache) that caches the SSR-rendered HTML page could inadvertently cache and leak one user's private data to other users, leading to a high-severity information disclosure vulnerability. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.
Frequently asked questions
- What is CVE-2026-50170?
- Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a vulnerability was discovered in @angular/common when Server-Side Rendering (SSR) and hydration are enabled. The HttpTransferCache utility optimizes hydration by caching outgoing HTTP requests performed during SSR and transferring the cached state to the client-side application via TransferState. However, the caching mechanism fails to inspect the withCredentials flag or the Cookie header of outgoing requests. As a result, credentialed, user-specific responses may be cached by default in the shared TransferState payload. When these responses are serialized into the HTML, any caching layer (such as a CDN, reverse proxy, or shared server cache) that caches the SSR-rendered HTML page could inadvertently cache and leak one user's private data to other users, leading to a high-severity information disclosure vulnerability. This vulnerability is fixed in 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23.
- How severe is CVE-2026-50170?
- CVE-2026-50170 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-50170 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (19th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-50170?
- CVE-2026-50170 primarily affects Angular. In total, 16 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-50170?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- Does CVE-2026-50170 have an EU (EUVD) identifier?
- Yes. CVE-2026-50170 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-38292.
- When was CVE-2026-50170 published?
- CVE-2026-50170 was published on 2026-06-22 and last updated on 2026-07-09.
References
- https://github.com/angular/angular/pull/67964
- https://github.com/angular/angular/security/advisories/GHSA-q6f4-qqrg-jv6x
Affected products (16)
- cpe:2.3:a:angular:angular:*:*:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next0:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next1:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next10:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next11:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next12:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next2:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next3:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next4:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next5:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next6:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next7:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next8:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:next9:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:rc0:*:*:*:node.js:*:*
- cpe:2.3:a:angular:angular:22.0.0:rc1:*:*:*:node.js:*:*
More vulnerabilities in Angular
- CVE-2026-50168 — High (CVSS 8.2): Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and…
- CVE-2026-54268 — High (CVSS 7.5): Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and…
- CVE-2026-69151 — Medium (CVSS 6.1): Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and…
- CVE-2026-69149 — Medium (CVSS 6.1): Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and…
- CVE-2026-68945 — Medium (CVSS 6.1): Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and…
- CVE-2026-50556 — Medium (CVSS 6.1): Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and…
Other CWE-524 vulnerabilities
- CVE-2026-53943 — Critical (CVSS 9.6): Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that…
- CVE-2025-64762 — Critical (CVSS 9.1): The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS &…
- CVE-2026-61836 — High (CVSS 8.6): Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching…
- CVE-2026-71316 — High (CVSS 7.5): Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries…
- CVE-2026-65755 — High (CVSS 7.5): Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere…
- CVE-2026-64792 — High (CVSS 7.5): Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs…