GHSA-qxh6-94w6-9r5p
HIGHCVE-2026-54264An information disclosure vulnerability exists in the @angular/service-worker package of the Angular framework. When the Service Worker fetches assets, it preserves metadata (such as headers) from the original request. However, on cross-origin redirects, the Service Worker fails to strip sensitive headers, violating the Fetch redirect algorithm.
- Affected
- >= 22.0.0-next.0, < 22.0.1, >=22.0.0-next.0, <22.0.1
- Fixed in
- 22.0.1
- Weakness
- CWE-200
- Published
- 2026-06-15
- Source
- github