Medium [CVE-2026-54267] @angular/core: Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
This medium-severity Red Hat Linux advisory covers CVE-2026-54267.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, to optimize client-side bootstrap in Server-Side Rendered (SSR) environments, Angular supports Hydration via provideClientHydration().
During SSR, Angular serializes the application's runtime state (such as cached HttpClient responses) and outputs it into the HTML stream as a
- < 22.0.1
- < 21.2.17
- < 20.3.25
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
- 22.0.1
- 21.2.17
- 20.3.25
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
Mitigation checklist
- No mitigation is required. Red Hat products are not affected by this vulnerability, as detailed in the statement above.
Official advisory · high-confidence parse· fetched 14 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.