Skip to content

Security Alert – CVE-2026-54266 #50

Description

@github-actions

General Information

  • Title: @angular/common: Weak 32-Bit Cache Key Hashing in HttpTransferCache Leading to Cross-Request Data Leakage and State Poisoning
  • Category: vulnerabilities
  • Severity: high
  • Published date: 2026-06-22
  • Short Description: @angular/common: Weak 32-Bit Cache Key Hashing in HttpTransferCache Leading to Cross-Request Data Leakage and State Poisoning

Affected Package

  • Package name: @angular/common
  • Fixed version: 22.0.1, 21.2.17, 20.3.25

Classification

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicA bigger feature that needs more deliverable subtasks to finishscope:securitySecurity, auth, compliancetype:tech-debtMarks task as a tech-debt item

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions