Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities Moderate
CVE-2026-50169 was published for @angular/service-worker (npm) Jun 15, 2026
Yenya030 Credited to Yenya030, alan-agius4, JeanMeche, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
JeanMeche JeanMeche josephperrott josephperrott AndrewKushnir AndrewKushnir
@angular/service-worker: Request Credential & Cache Policy Stripping Moderate
CVE-2026-50184 was published for @angular/service-worker (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, josephperrott, AndrewKushnir, alan-agius4, and JeanMeche josephperrott josephperrott
AndrewKushnir AndrewKushnir alan-agius4 alan-agius4 JeanMeche JeanMeche
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS) Moderate
CVE-2026-54265 was published for @angular/compiler (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, JeanMeche, and JoostK alan-agius4 alan-agius4
JeanMeche JeanMeche JoostK JoostK
SkyZeroZx Credited to SkyZeroZx, josephperrott, alan-agius4, and JeanMeche josephperrott josephperrott
alan-agius4 alan-agius4 JeanMeche JeanMeche
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` Moderate
CVE-2026-88059 was published for @angular/common (npm) Sep 10, 2026
JeanMeche Credited to JeanMeche, alan-agius4, and SkyZeroZx alan-agius4 alan-agius4
SkyZeroZx SkyZeroZx
ProTip! Advisories are also available from the GraphQL API