{"id":"CVE-2026-101896","aliases":["GHSA-ff3f-86qr-9cv3"],"title":"Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters","summary":"Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters","severity":"high","cwe":["CWE-400","CWE-770"],"vendor":"angular","product":"@angular/router","ecosystem":"npm","affected":["@angular/router >= 22.0.0, < 22.2.0","@angular/router >= 21.0.0, < 21.2.24","@angular/router >= 20.0.0, < 20.3.32","@angular/router <= 19.2.25"],"patched":["@angular/router 22.2.0","@angular/router 21.2.24","@angular/router 20.3.32"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T15:40:48Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-ff3f-86qr-9cv3","references":[{"url":"https://github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3"},{"url":"https://github.com/angular/angular/issues/70716"},{"url":"https://github.com/angular/angular/pull/70717"},{"url":"https://github.com/angular/angular/commit/03872a80bcf1c89b2b04cdd3f444b2ee954da583"},{"url":"https://github.com/angular/angular/commit/5af61216eab8bf4a6697a1d79bda3d857c06f89d"},{"url":"https://github.com/angular/angular/commit/ddfe21072ba32ca4cd9d7d3c6b7df66af81d58c4"},{"url":"https://github.com/advisories/GHSA-ff3f-86qr-9cv3"}],"tags":["ghsa","npm"],"ingestedAt":"2026-09-30T16:10:06.871Z","slug":"CVE-2026-101896","body":"## Overview\n\nA denial of service (DoS) vulnerability was identified in `@angular/router` when Server-Side Rendering (SSR) is enabled on Node.js (V8).\n\nWhen `@angular/router` parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (`Record<string, string>`). When matrix parameter names or outlet names are numeric strings (such as `/a;990;2522`), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.\n\nUnder V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (`HOLEY_ELEMENTS`) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like `990` followed by `2522`) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.\n\nBecause each segment in a URL path allocates its own independent `parameters` object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately **~350x**.\n\n### Impact\n\nSuccessful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable `JavaScript heap out of memory` fatal error and causing a Denial of Service.\n\n* **High Amplification:** A single 11-byte segment (`/a;990;2522`) consumes ~20 KB–25 KB of V8 heap.\n* **Low Concurrency Required:**\n  * With 8 KB request paths (~740 segments, within default Nginx 8 KB buffer limits), as few as **12–22 concurrent requests** crash a 256 MiB–512 MiB Node.js SSR worker.\n  * With smaller 1 KB–2 KB request paths (~90–180 segments), a burst of ~50–100 concurrent requests achieves the same heap exhaustion.\n* **Client-side SPAs Unaffected:** Pure client-side Angular applications (Single Page Applications without SSR) are **not** vulnerable, as local browser memory consumption does not cross a security boundary.\n\n### Attack Preconditions & Vulnerable Configurations\n\nAn application is affected only if **all** of the following conditions are met:\n\n* **SSR Enabled:** The application runs in a Server-Side Rendering environment powered by Node.js / V8.\n* **Direct Router Parsing:** User-controlled request URLs are parsed by `@angular/router` during SSR.\n* **No Reverse-Proxy Semicolon/Segment Filtering:** Upstream reverse proxies (Nginx, Cloudflare, ALB) forward URLs containing semicolons (`;`) and multiple path segments without stripping or rejecting them.\n\n#### Exploit Payload Example\n\nAn attacker sends concurrent HTTP requests with repeated numeric matrix parameters:\n\n```http\nGET /a;990;2522/a;990;2522/a;990;2522/... HTTP/1.1\nHost: example.com\n```\n\nEven with paths under 2 KB, overlapping requests during SSR will rapidly consume the V8 heap until the process crashes.\n\n### Patches\n\nThe issue is resolved by updating `@angular/router` to enforce V8 dictionary elements storage (`setUrlDerivedKey`) for numeric URL-derived keys (index >= 32). This prevents V8 from allocating oversized contiguous array backing stores while preserving route matching, parameter values, and component input bindings.\n\n* `22.2.0`\n* `21.2.24`\n* `20.3.32`\n\n### Workarounds & Mitigations\n\nIf you cannot immediately upgrade to a patched version, apply one of the following mitigations at your edge or reverse proxy:\n\n1. **Block or Sanitize Matrix Parameters at the Reverse Proxy:**  \n   Configure your reverse proxy (e.g., Nginx, Cloudflare, or AWS WAF) to reject or strip semicolons (`;`) in request paths before forwarding requests to the Angular SSR service:\n   ```nginx\n   # Nginx example: reject requests containing matrix parameters\n   if ($uri ~* \";\") {\n       return 400;\n   }\n   ```\n2. **Enforce Strict Path Segment Limits:**  \n   Reject requests with excessive path depth (e.g., more than 20–30 segments).\n3. **Increase Node.js Old Space:**  \n   Increase `--max-old-space-size` (e.g., to 2048 or 4096 MB) to increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.\n\n## Affected packages\n\n- `@angular/router >= 22.0.0, < 22.2.0`\n- `@angular/router >= 21.0.0, < 21.2.24`\n- `@angular/router >= 20.0.0, < 20.3.32`\n- `@angular/router <= 19.2.25`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@angular/router 22.2.0`\n- `@angular/router 21.2.24`\n- `@angular/router 20.3.32`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}