@angular/service-worker is vulnerable to Information Disclosure
57
Medium Risk
Angular service worker reconstructs intercepted requests without preserving explicit credential and cache policy options. Requests that applications mark with credentials: 'omit' or cache: 'no-store' can be replayed with browser-default credentials or cached in service worker storage when they match configured asset groups. This can expose same-origin session data or keep private responses available after logout in affected client configurations. The patch preserves credential and cache policy fields when reconstructing requests.
You are affected if you are using a version that falls within the vulnerable range.
@angular/service-worker is vulnerable to Information Disclosure in versions 21.0.0 - 21.2.14, 20.0.0 - 20.3.21 and 19.0.0 - 19.2.22.
Upgrade the @angular/service-worker library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant