chore(deps): update dependency @angular/common to v22.1.1 [security] - #261
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
View your CI Pipeline Execution ↗ for commit cdc9ec2
☁️ Nx Cloud last updated this comment at |
This PR contains the following updates:
22.1.0→22.1.1Angular: Information Leak via
HttpTransferCacheBypass When UsingwithRequestsMadeViaParentCVE-2026-88059 / GHSA-p297-fm68-3q8c
More information
Details
A security bypass vulnerability was discovered in
@angular/commonwhen Server-Side Rendering (SSR) and hydration are enabled in applications using a hierarchicalHttpClientconfiguration withwithRequestsMadeViaParent().The
HttpTransferCacheutility optimizes hydration by caching outgoing HTTP requests performed during SSR and transferring the cached state to the client-side application viaTransferState(serialized as JSON in<script id="ng-state">). Following the remediation of CVE-2026-50170,HttpTransferCacheautomatically skips caching requests that contain authentication headers or credentials (Authorization,Cookie,withCredentials, etc.).However, when a child
HttpClientdelegates to a parent client viawithRequestsMadeViaParent(), the child'sTransferCacheinterceptor evaluates whether the request is eligible for caching before delegating to the parent client's interceptor chain.If an outgoing request originates as anonymous from the child client, the child
TransferCachemarks the request as cacheable. When the request reaches a parent interceptor that injects sensitive authentication credentials (such as anAuthorizationheader or API token), the parentTransferCachecorrectly skips caching the authenticated request. However, when the backend returns the private, authenticated response, the childTransferCachestill stores the response inTransferStatebased on its initial pre-delegation evaluation.Impact
Successful exploitation allows sensitive, user-specific information belonging to an authenticated user to be leaked to unauthenticated or unauthorized users. This occurs when:
HttpClientinitiates an unauthenticated request that is subsequently authenticated by a parent interceptor.TransferState).Attack Preconditions & Vulnerable Configurations
An application is affected only if all of the following conditions are met:
provideClientHydration()).HttpClientwith Delegation: The application configures a childHttpClientusingwithRequestsMadeViaParent().Authorizationheaders, session cookies, or custom API tokens filtered viawithHttpTransferCacheOptions) are attached by an interceptor in the parent injector chain rather than on the initial child request.Vulnerable Code Pattern Example
Patches
The issue is resolved by updating
@angular/commonto run root interceptors in the terminal request chain so that delegated clients leave inherited root interceptors to the parent chain, preventing duplicate execution and ensuringHttpTransferCacheevaluates cache eligibility after parent request interceptors run.22.1.121.2.2020.3.28Workarounds & Mitigations
For applications that cannot immediately upgrade to a patched version, use one of the following mitigations:
Authorization) are attached directly when constructing the request or via an interceptor configured directly on the childHttpClient, rather than relying solely on parent interceptors.withHttpTransferCacheOptionswith a filter on the child client that explicitly excludes endpoints returning user-specific or sensitive data:Cache-Control: no-store/privateheaders at your edge/CDN layer so personalized HTML is never shared.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
angular/angular (@angular/common)
v22.1.1Compare Source
core
http
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.