CVE-2026-101895High▾ TwilightAngular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A Denial of Service (DoS) vulnerability exists in @angular/platform-server's DOM emulation parser (domino). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as <!DOCTYPE html ), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process.
In Angular Server-Side Rendering (SSR), @angular/platform-server uses domino to parse and sanitize HTML bound through template bindings (such as [innerHTML]) or manipulated via DOM APIs.
In Domino's HTML parser (lib/HTMLParser.js), tokenizer states that specify fixed lookahead—such as after_doctype_name_state (lookahead = 6)—rely on the state handler function to explicitly advance the character index pointer (nextchar). While branches for whitespace, >, and keyword matching advance nextchar, the EOF branch (case -1: // EOF) emitted doctype and EOF tokens without advancing nextchar or transitioning out of the state:
case -1: // EOF
forcequirks();
emitDoctype();
emitEOF();
break;
Because nextchar remained unchanged pointing to the EOF marker character (\uFFFF), the scanner loop (while (nextchar < numchars)) repeatedly re-invoked after_doctype_name_state with codepoint = EOF indefinitely. In Node.js's single-threaded runtime, this synchronous loop starves the event loop entirely.
[innerHTML], interpolated into markup, or sanitized on the server.<!DOCTYPE html ). The Node.js SSR process locks up at 100% CPU and ceases responding to all concurrent and subsequent HTTP requests.Proof of Concept:
import { Component } from '@angular/core';
@Component({
selector: 'app-root',
standalone: true,
template: `<div [innerHTML]="payload"></div>`,
})
export class AppComponent {
// Attacker-controlled input containing an incomplete DOCTYPE ending with whitespace
payload = '<!DOCTYPE html ';
}
[innerHTML] in server-rendered templates; use standard text interpolation ({{ userInput }}) or [textContent] when raw HTML rendering is not required.[innerHTML] on the server by stripping or rejecting strings matching /^<!DOCTYPE/i.@angular/platform-server >= 22.0.0, < 22.1.6@angular/platform-server >= 21.0.0, < 21.2.23@angular/platform-server >= 20.0.0, < 20.3.31@angular/platform-server <= 19.2.25Upgrade to a patched release:
@angular/platform-server 22.1.6@angular/platform-server 21.2.23@angular/platform-server 20.3.31Connected by shared product, vendor, weakness, or advisory.
CVE-2026-69149HighAngular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
CVE-2026-50168High@angular/platform-server: URL Parser Differential leading to SSRF Allowlist Bypass
CVE-2026-50171High@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVE-2026-50555High@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-54268High@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
CVE-2025-48392High· 7.5A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0.4. Users are recommended to upgrade to version 2.0.5, which fixes the issue.