A high-severity vulnerability in Angular's @angular/common/http package allows semantically different HttpClient requests to collide on the same HttpTransferCache key during Server-Side Rendering and client-side hydration, enabling cross-request response reuse and client-side state poisoning. The flaw, tracked as CVE-2026-68945, stems from ambiguous query-parameter serialization in cache-key generation, including cases where repeated parameters are comma-joined or attacker-controlled delimiters such as & and = produce identical serialized forms.
The issue is remotely exploitable without authentication and carries a CVSS 4.0 score of 8.8. Angular fixed the bug by replacing custom serialization logic with native URLSearchParams sorting and encoding, and released patched versions 20.3.27, 21.2.19, and 22.0.2; versions prior to those releases are affected. Public references include Angular commits, a pull request, and a GitHub security advisory documenting the remediation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-68945 was published as a high-severity vulnerability affecting Angular's HttpTransferCache in @angular/common. The flaw allows semantically different requests to collide on the same cache key, enabling cross-request response reuse and client-side state poisoning.
Angular patched the HttpTransferCache cache-key ambiguity issue in @angular/common by replacing custom parameter serialization with native URLSearchParams sorting and encoding. Fixed versions include 20.3.27, 21.2.19, and 22.0.2, and the advisory states the patches were released on the same day.
Angular committed a change to its HTTP transfer cache logic that replaced custom parameter normalization with URLSearchParams sorting and serialization, preventing cache-key collisions between comma-separated scalar values and repeated query parameters. The commit also added a regression test verifying that `role=user,admin` and `role=user&role=admin` are cached distinctly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.