CVE-2026-54268High▾ Twilight@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
0.3% → 0.6%
A Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, which is also utilized by the standard Angular DatePipe, does not properly limit or validate the length of the format parameter.
When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS).
In Angular applications that leverage Server-Side Rendering, an attacker can supply a malicious payload with an excessively long date format string. Processing this on the server causes high CPU usage and triggers a JavaScript heap out of memory crash, rendering the application unavailable to all users.
In standard client-side applications, executing the vulnerable function with an excessively long format string blocks the browser's main thread, causing the browser tab to freeze and become completely unresponsive.
For this vulnerability to be exploitable, both of the following conditions must be met:
formatDate utility or the DatePipe.If the date format is hardcoded (e.g., 'mediumDate', 'shortTime', or static strings) or properly validated to be within a reasonable length limit, the application is not vulnerable.
@angular/common >= 22.0.0-next.0, < 22.0.1@angular/common >= 21.0.0-next.0, < 21.2.17@angular/common >= 20.0.0-next.0, < 20.3.25@angular/common <= 19.2.25Upgrade to a patched release:
@angular/common 22.0.1@angular/common 21.2.17@angular/common 20.3.25Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50171High@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)
CVE-2026-68945HighAngular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning
CVE-2026-50170High@angular/common: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache
CVE-2026-54266High@angular/common: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning
CVE-2026-24001High· 7.5jsdiff is a JavaScript text differencing implementation
GHSA-j95f-988m-3j2fHighTiptap: Quadratic ReDoS in block and inline Markdown attribute parsing