@angular/service-worker is vulnerable to Information Disclosure
57
Medium Risk
Angular service worker reconstructs intercepted requests without preserving strict redirect handling. Requests that applications create with redirect: 'error' can be downgraded to the browser's default follow behavior when they match configured asset groups. In applications where public matched routes redirect to authenticated same-origin resources, the service worker can act as a confused deputy and return sensitive data that the original request policy intended to block. The patch preserves redirect policy when reconstructing requests.
You are affected if you are using a version that falls within the vulnerable range.
@angular/service-worker is vulnerable to Information Disclosure in versions 21.0.0 - 21.2.14, 20.0.0 - 20.3.21 and 19.0.0 - 19.2.22.
Upgrade the @angular/service-worker library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant