CVE-2026-101896High▾ TwilightAngular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A denial of service (DoS) vulnerability was identified in @angular/router when Server-Side Rendering (SSR) is enabled on Node.js (V8).
When @angular/router parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as /a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.
Under V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like 990 followed by 2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.
Because each segment in a URL path allocates its own independent parameters object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.
Successful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable JavaScript heap out of memory fatal error and causing a Denial of Service.
/a;990;2522) consumes ~20 KB–25 KB of V8 heap.An application is affected only if all of the following conditions are met:
@angular/router during SSR.;) and multiple path segments without stripping or rejecting them.An attacker sends concurrent HTTP requests with repeated numeric matrix parameters:
GET /a;990;2522/a;990;2522/a;990;2522/... HTTP/1.1
Host: example.com
Even with paths under 2 KB, overlapping requests during SSR will rapidly consume the V8 heap until the process crashes.
The issue is resolved by updating @angular/router to enforce V8 dictionary elements storage (setUrlDerivedKey) for numeric URL-derived keys (index >= 32). This prevents V8 from allocating oversized contiguous array backing stores while preserving route matching, parameter values, and component input bindings.
22.2.021.2.2420.3.32If you cannot immediately upgrade to a patched version, apply one of the following mitigations at your edge or reverse proxy:
;) in request paths before forwarding requests to the Angular SSR service:
# Nginx example: reject requests containing matrix parameters
if ($uri ~* ";") {
return 400;
}
--max-old-space-size (e.g., to 2048 or 4096 MB) to increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.@angular/router >= 22.0.0, < 22.2.0@angular/router >= 21.0.0, < 21.2.24@angular/router >= 20.0.0, < 20.3.32@angular/router <= 19.2.25Upgrade to a patched release:
@angular/router 22.2.0@angular/router 21.2.24@angular/router 20.3.32Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101895HighAngular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
CVE-2024-12254High· 7.5Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"
CVE-2026-50171High@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVE-2026-54268High@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
CVE-2026-25535High· 7.5jsPDF is a library to generate PDFs in JavaScript
CVE-2026-102278High· 7.5The brace-expansion library generates arbitrary strings containing a common prefix and suffix