VDB
KO
HIGH

GHSA-jhpw-976m-542j

Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning

Quick fix

GHSA-jhpw-976m-542j — @angular/common: upgrade to the fixed version with the command below.

npm install @angular/common@22.0.2

Details

Angular's `HttpTransferCache` caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration.

During SSR, `HttpTransferCache` previously generated identical key material for distinct request parameters when repeated values were present because repeated values were joined with commas:

```ts new HttpParams().set('role', 'user,admin') new HttpParams().append('role', 'user').append('role', 'admin') ```

Both requests previously serialized as `role=user,admin`, allowing distinct `HttpClient` requests to produce the same transfer-cache key material.

### Impact

In an SSR application, this cache-key ambiguity can make a later security-sensitive `HttpClient` request receive the response from an earlier semantically different request in the same render. For example, an attacker-influenced scalar-comma request can be cached and then replayed as the response for a trusted repeated-param authorization or data request to the same URL. As a result, Angular's server-rendered output can be based on the wrong backend response because the trusted request is not dispatched. This can lead to:

- **State Poisoning**: Using incorrect or attacker-influenced cached responses for subsequent application logic. - **Cross-Request Response Reuse**: Reusing cached responses across requests with semantically different parameters.

### Patched Versions

- 22.0.2 - 21.2.19 - 20.3.27

### Workarounds

If you cannot upgrade immediately, configure your `HttpClient` requests to skip transfer caching for sensitive endpoints where repeated parameter keys are used:

```ts this.http.get('/api/resource', { transferCache: false }); ```

Alternatively, disable the HTTP transfer cache globally in your application bootstrap config:

```ts import { provideClientHydration, withNoHttpTransferCache } from '@angular/platform-browser';

export const appConfig = { providers: [ provideClientHydration( withNoHttpTransferCache() ) ] }; ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @angular/common
Introduced in: 22.0.0-next.0 Fixed in: 22.0.2
Fix npm install @angular/common@22.0.2
npm / @angular/common
Introduced in: 21.0.0-next.0 Fixed in: 21.2.19
Fix npm install @angular/common@21.2.19
npm / @angular/common
Introduced in: 20.0.0-next.0 Fixed in: 20.3.27
Fix npm install @angular/common@20.3.27
npm / @angular/common
Introduced in: 0

No fixed version published yet for @angular/common (npm). Pin to a known-safe version or switch to an alternative.

References