THREAT OPS › Threat News › [GHSA] GHSA-jhpw-976m-542j (high) — Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
[GHSA] GHSA-jhpw-976m-542j (high) — Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
GHSA-jhpw-976m-542j Severity: high CVE: CVE-2026-68945
Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
Angular's `HttpTransferCache` caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration.
During SSR, `HttpTransferCache` previously generated identical key material for dist
Indicators of compromise
- CVE-2026-68945cve
Original source: https://github.com/advisories/GHSA-jhpw-976m-542j