@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker (CVE-2026-54264)
An information disclosure vulnerability in the @angular/service-worker package allows sensitive headers such as Authorization tokens or session cookies to be leaked during cross-origin redirects. When the Angular Service Worker fetches assets with credentialed requests and encounters a redirect to an untrusted origin, it improperly forwards sensitive headers to the new origin. This can expose critical credentials to unauthorized third parties. The issue affects versions up to and including 19.2.25 and is patched in versions 20.3.25, 21.2.17, and 22.0.1.
AI Analysis
Technical Summary
The @angular/service-worker package in Angular improperly preserves sensitive request headers (e.g., Authorization, Proxy-Authorization, cookies) when handling cross-origin redirects during asset fetching. This behavior violates the Fetch redirect algorithm, which requires stripping such headers on cross-origin redirects. As a result, an attacker controlling the redirect destination can obtain sensitive credentials. Exploitation requires the application to use the vulnerable service worker version, send credentialed requests, and have those requests redirected cross-origin to an attacker-controlled domain. Patched versions include 20.3.25, 21.2.17, and 22.0.1.
Potential Impact
Sensitive credentials such as Authorization tokens, Proxy-Authorization headers, or session cookies can be exposed to unauthorized third-party servers if a cross-origin redirect occurs during asset fetching by the Angular Service Worker. This can lead to information disclosure and potential unauthorized access to user accounts or services relying on those credentials.
Mitigation Recommendations
Upgrade the @angular/service-worker package to one of the patched versions: 20.3.25, 21.2.17, or 22.0.1. These versions contain fixes that prevent sensitive headers from being forwarded on cross-origin redirects. Until upgrading, avoid configurations that send credentialed requests which may be redirected cross-origin.
@angular/service-worker: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker (CVE-2026-54264)
Description
An information disclosure vulnerability in the @angular/service-worker package allows sensitive headers such as Authorization tokens or session cookies to be leaked during cross-origin redirects. When the Angular Service Worker fetches assets with credentialed requests and encounters a redirect to an untrusted origin, it improperly forwards sensitive headers to the new origin. This can expose critical credentials to unauthorized third parties. The issue affects versions up to and including 19.2.25 and is patched in versions 20.3.25, 21.2.17, and 22.0.1.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The @angular/service-worker package in Angular improperly preserves sensitive request headers (e.g., Authorization, Proxy-Authorization, cookies) when handling cross-origin redirects during asset fetching. This behavior violates the Fetch redirect algorithm, which requires stripping such headers on cross-origin redirects. As a result, an attacker controlling the redirect destination can obtain sensitive credentials. Exploitation requires the application to use the vulnerable service worker version, send credentialed requests, and have those requests redirected cross-origin to an attacker-controlled domain. Patched versions include 20.3.25, 21.2.17, and 22.0.1.
Potential Impact
Sensitive credentials such as Authorization tokens, Proxy-Authorization headers, or session cookies can be exposed to unauthorized third-party servers if a cross-origin redirect occurs during asset fetching by the Angular Service Worker. This can lead to information disclosure and potential unauthorized access to user accounts or services relying on those credentials.
Mitigation Recommendations
Upgrade the @angular/service-worker package to one of the patched versions: 20.3.25, 21.2.17, or 22.0.1. These versions contain fixes that prevent sensitive headers from being forwarded on cross-origin redirects. Until upgrading, avoid configurations that send credentialed requests which may be redirected cross-origin.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qxh6-94w6-9r5p
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-54264"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a58b41068715ace43d67d78
Added to database: 07/16/2026, 10:36:00 UTC
Last enriched: 07/16/2026, 10:53:35 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.