boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-88059

Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  L  N  N    5.8   .0034   25.0     —
AFFECTED
  Product  Versions      Fixed
  angular  <= 19.2.25 –  —
TIMELINE
  Sep 9   Reserved by GitHub_M
  Sep 10  Published (CNA: GitHub_M)
  Sep 29  EXPLOIT PUBLISHED — CVE-2026-88059 (angular). Public exploit reference added.
  Sep 29  RESCORED — CVE-2026-88059 (angular). CVSS 4 → 5.8 (NVD).
CWE-200, CWE-524 · CNA: GitHub_M · CVSS v3.1 · 9 references · NVD status: Analyzed

Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authenticated response when Server-Side Rendering (SSR) and hydration use a hierarchical HttpClient configured with withRequestsMadeViaParent. The child TransferCache evaluates an initially anonymous request before delegation, then a parent withInterceptors chain adds an Authorization header, cookie, or API token; although the parent cache skips the authenticated request, the child still stores the private response in TransferState serialized as JSON in the ng-state script. Exploitation requires provideClientHydration, child provideHttpClient delegation through withRequestsMadeViaParent, parent-level credential injection, and an SSR HTML response shared across users by a CDN, reverse proxy, or application cache. A later unauthenticated or unauthorized visitor can receive the cached HTML containing the earlier authenticated user's sensitive response data. Applications can mitigate by attaching credentials at the child, filtering sensitive endpoints with withHttpTransferCacheOptions, disabling transfer caching for sensitive routes, or marking personalized HTML private or no-store. This issue is fixed in versions 20.3.28, 21.2.20, and 22.1.1.

Lifecycle

Complete event history — 4 events, chronological
DateEventDetail
September 9, 2026ReservedReserved by GitHub_M
September 10, 2026PublishedPublished (CNA: GitHub_M)
September 29, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-88059 (angular). Public exploit reference added.
September 29, 2026RESCOREDRESCORED — CVE-2026-88059 (angular). CVSS 4 → 5.8 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
angularangular—<= 19.2.25—

Weaknesses

CWE-200 · CWE-524

References (9)

Related

Authoritative record: CVE-2026-88059 at cve.org

Vendors: angular

Weaknesses: CWE-200 · CWE-524

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-88059 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.