CVE-2026-88059
mediumCVSS v3 Base Score
4.0
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
Attack Characteristics
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Confidentiality
Low
Integrity
None
Availability
None
Published: September 10, 2026 (0 days ago)
Last Modified: September 10, 2026
Vendor: Red Hat
Source: REDHAT
Vulnerability Report
Generated by CyberWatcher
Description
A flaw was found in Angular. When Server-Side Rendering (SSR) and hydration are used with a hierarchical HttpClient configured with `withRequestsMadeViaParent`, the `HttpTransferCache` can improperly cache authenticated responses. This occurs because a child TransferCache stores private response data in TransferState even when a parent HttpClient chain adds credentials and skips the authenticated request. Consequently, a later unauthenticated or unauthorized visitor could receive cached HTML containing sensitive data from a previously authenticated user, leading to information disclosure.
CWE
CWE-524Affected Products
A-MQ Interconnect 1Red Hat Ceph Storage 4Red Hat Enterprise Linux 10Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9Red Hat Fuse 7Red Hat OpenStack Platform 16.2Red Hat Quay 3Red Hat Single Sign-On 7