THREAT OPS › Threat News › [GHSA] GHSA-p297-fm68-3q8c (medium) — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
[GHSA] GHSA-p297-fm68-3q8c (medium) — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
GHSA-p297-fm68-3q8c Severity: medium CVE: CVE-2026-88059
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
A security bypass vulnerability was discovered in `@angular/common` when Server-Side Rendering (SSR) and hydration are enabled in applications using a hierarchical `HttpClient` configuration with `withRequestsMadeViaParent()`.
The `HttpTransfer
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-88059cve
- CVE-2026-50170cve
Original source: https://github.com/advisories/GHSA-p297-fm68-3q8c