GHSA-jhpw-976m-542j
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
Quick fix
GHSA-jhpw-976m-542j — @angular/common: upgrade to the fixed version with the command below.
npm install @angular/common@22.0.2 Details
Angular's `HttpTransferCache` caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration.
During SSR, `HttpTransferCache` previously generated identical key material for distinct request parameters when repeated values were present because repeated values were joined with commas:
```ts new HttpParams().set('role', 'user,admin') new HttpParams().append('role', 'user').append('role', 'admin') ```
Both requests previously serialized as `role=user,admin`, allowing distinct `HttpClient` requests to produce the same transfer-cache key material.
### Impact
In an SSR application, this cache-key ambiguity can make a later security-sensitive `HttpClient` request receive the response from an earlier semantically different request in the same render. For example, an attacker-influenced scalar-comma request can be cached and then replayed as the response for a trusted repeated-param authorization or data request to the same URL. As a result, Angular's server-rendered output can be based on the wrong backend response because the trusted request is not dispatched. This can lead to:
- **State Poisoning**: Using incorrect or attacker-influenced cached responses for subsequent application logic. - **Cross-Request Response Reuse**: Reusing cached responses across requests with semantically different parameters.
### Patched Versions
- 22.0.2 - 21.2.19 - 20.3.27
### Workarounds
If you cannot upgrade immediately, configure your `HttpClient` requests to skip transfer caching for sensitive endpoints where repeated parameter keys are used:
```ts this.http.get('/api/resource', { transferCache: false }); ```
Alternatively, disable the HTTP transfer cache globally in your application bootstrap config:
```ts import { provideClientHydration, withNoHttpTransferCache } from '@angular/platform-browser';
export const appConfig = { providers: [ provideClientHydration( withNoHttpTransferCache() ) ] }; ```
Are you affected?
Enter the version of the package you're using.
Affected packages
22.0.0-next.0 Fixed in: 22.0.2 npm install @angular/common@22.0.2 21.0.0-next.0 Fixed in: 21.2.19 npm install @angular/common@21.2.19 20.0.0-next.0 Fixed in: 20.3.27 npm install @angular/common@20.3.27 0 No fixed version published yet for @angular/common (npm). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/angular/angular/security/advisories/GHSA-jhpw-976m-542j [WEB]
- https://github.com/angular/angular/pull/68571 [WEB]
- https://github.com/angular/angular/commit/6867f77ec779a0a24f6339ad6c775f444202103c [WEB]
- https://github.com/angular/angular/commit/948a8d6831e8920b54663ec79421da95210e0e35 [WEB]
- https://github.com/angular/angular/commit/a64e2883e9dc4abdac70209129be303de79e5b2b [WEB]
- https://github.com/angular/angular/commit/a6c7fc5c13e6e494a4c9bd8e773b8d4b2a99b20c [WEB]
- https://github.com/angular/angular [PACKAGE]