Angular Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2026-50169
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2 21.2.15 20.3.22 and 19.2.23 an issue in the angular/service-worker package compromises the integrity of request-policy enforcement during request reconstruction. When the Angular Service Worker intercepts network requests for matched assets it reconstructs a new Request object using an internal helper function. During this reconstruction process the helper function strips the strict client-defined request redirect policy configuration (such as redirect: 39error39) falling back to the browser39s default 39follow39 strategy. If the target web application makes client-side requests with a strict policy (e.g. expecting a network error instead of automatically following redirects) the service worker will bypass this instruction and automatically follow HTTP 3xx redirects to other destinations. This acts as an unintended proxy/intermediary (quotConfused Deputyquot) and can result in cookie/credential exposure or same-origin session-restricted data leakage if public dynamic routes redirect to sensitive routes. This vulnerability is fixed in 22.0.0-rc.2 21.2.15 20.3.22 and 19.2.23.