Use of Cache Containing Sensitive Information Affecting @angular/service-worker package, versions <19.2.23>=20.0.0-next.0 <20.3.22>=21.0.0-next.0 <21.2.15>=22.0.0-next.0 <22.0.0-next.4


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.17% (7th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ANGULARSERVICEWORKER-17359086
  • published17 Jun 2026
  • disclosed15 Jun 2026
  • creditUnknown

Introduced: 15 Jun 2026

CVE-2026-50169  (opens in a new tab)
CWE-441  (opens in a new tab)
CWE-524  (opens in a new tab)

How to fix?

Upgrade @angular/service-worker to version 19.2.23, 20.3.22, 21.2.15, 22.0.0-next.4 or higher.

Overview

@angular/service-worker is an Angular - service worker tooling!

Affected versions of this package are vulnerable to Use of Cache Containing Sensitive Information in the request reconstruction. An attacker can access sensitive session-restricted data or expose credentials by exploiting automatic redirect handling when a service worker intercepts requests and strips strict redirect policies.

Note: This is only exploitable if the application uses an active Angular Service Worker, has asset group patterns matching dynamic endpoints, the server issues HTTP 3xx redirects from public to private routes, the user has an active authenticated session, and the client initiates fetch requests with strict redirect parameters.

Workaround

This vulnerability can be mitigated by refactoring server routes to avoid public-to-private dynamic redirection, applying strict cookie flags, and excluding secure endpoints from service worker asset groups in the configuration.

CVSS Base Scores

version 4.0
version 3.1