CVE-2026-68945Patch(angular / angular)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch angular angular systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.2, HttpTransferCache comma-joins repeated request parameters, allowing semantically distinct HttpClient requests to use the same transfer-cache key and reuse a wrong backend response. This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • angular

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-03); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
angular

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-03: 1Mentions · 2026-08-06: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-08-03: 108-0308-06
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-031
Patch1
2026-08-061
General1
Full discourse2 posts
  • 0xh3l1x@cgomezz_23
    General

    Well, two high findings on Google :) How exciting! Hehehe https://nvd.nist.gov/vuln/detail/CVE-2026-69151 https://nvd.nist.gov/vuln/detail/CVE-2026-68945 https://t.co/hm3lW7YNL5

    Post summary

    The tweet simply links to two high‑severity CVE entries on the NVD without providing further details or context.

    00010278
    696 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Multiple High-Severity Vulnerabilities Fixed in Angular Ecosystem Angular released patches addressing three high-severity flaws across its compiler, core, and SSR packages: 1️⃣ CVE-2026-68945 (8.8): SSR HttpTransferCache key collision leading to response reuse & cache poisoning | Affected: @angular/common 2️⃣ CVE-2026-69149 (8.6): SSR XSS via unescaped text nodes in DOM emulation (domino) | Affected: @angular/platform-server 3️⃣ CVE-2026-69151 (7.6): i18n pipeline XSS allowing translation files to inject JS via i18n-on* | Affected: @angular/compiler, @angular/core 👉 Impact: Cross-request state poisoning and arbitrary script execution | Upgrade to Angular 20.3.27, 21.2.19, or 22.0.2

    Post summary

    Angular has issued critical patches for three high‑severity vulnerabilities, advising users to upgrade to the latest releases to mitigate XSS and cache‑poisoning issues.

    00000103
    280 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appangularangular-node.js-

Explore more