GHSA-qxh6-94w6-9r5p
@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker
Quick fix
GHSA-qxh6-94w6-9r5p — @angular/service-worker: upgrade to the fixed version with the command below.
npm install @angular/service-worker@22.0.1Details
An information disclosure vulnerability exists in the `@angular/service-worker` package of the Angular framework. When the Service Worker fetches assets, it preserves metadata (such as headers) from the original request. However, on cross-origin redirects, the Service Worker fails to strip sensitive headers, violating the Fetch redirect algorithm.
This allows a remote attacker to obtain sensitive credentials (e.g., `Authorization` tokens, `Proxy-Authorization` credentials, or session cookies) by triggering a cross-origin redirect to an untrusted external origin.
### Impact If an application configured with the Angular Service Worker fetches assets with credential headers (such as `Authorization` header), and one of those requests is redirected to a different origin, the Service Worker will forward those headers to the new origin. This exposes critical credentials and session identifiers to unauthorized third-party servers.
### Attack Preconditions For this vulnerability to be exploitable: 1. **Vulnerable Configuration:** The application must utilize the `@angular/service-worker` package to fetch assets. 2. **Credentialed Requests:** The application must attach sensitive request headers (like `Authorization`, `Proxy-Authorization`, or rely on cookies) to asset-group requests. 3. **Redirect Flow:** These requests must encounter a cross-origin redirect to an attacker-controlled or untrusted domain.
### Patched Versions * 22.0.1 * 21.2.17 * 20.3.25
### Credits This vulnerability was discovered and reported by [CodeMender from Google DeepMind](https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/).
Are you affected?
Enter the version of the package you're using.
Affected packages
22.0.0-next.0Fixed in: 22.0.1npm install @angular/service-worker@22.0.121.0.0-next.0Fixed in: 21.2.17npm install @angular/service-worker@21.2.1720.0.0-next.0Fixed in: 20.3.25npm install @angular/service-worker@20.3.250No fixed version published yet for @angular/service-worker (npm). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/angular/angular/security/advisories/GHSA-qxh6-94w6-9r5p[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-54264[ADVISORY]
- https://github.com/angular/angular/pull/69029[WEB]
- https://github.com/angular/angular/commit/47d68dcb26266316647133ab6385e77fc3e5ae08[WEB]
- https://github.com/angular/angular[PACKAGE]