@angular/common is vulnerable to Insufficient Verification of Data Authenticity
88
High Risk
@angular/common contains a cache poisoning vulnerability in its Server-Side Rendering (SSR) HttpTransferCache. Ambiguous serialization of repeated HTTP query parameters can cause distinct requests to generate the same cache key, allowing an attacker-influenced response to be reused for a different security-sensitive request during client hydration. This may result in incorrect application state or unintended reuse of cached responses.
You are affected if you are using a version that falls within the vulnerable range and you are using Angular SSR with HttpTransferCache enabled and make security-sensitive HttpClient requests that use repeated query parameter keys.
@angular/common is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 20.3.26, 21.0.0 - 21.2.18 and 22.0.0 - 22.0.1.
Upgrade the @angular/common library to the patch version. If this is not possible, disable transfer caching for sensitive HttpClient requests (transferCache: false) or disable HttpTransferCache globally.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant