---
id: CVE-2026-54268
aliases:
  - GHSA-48r7-hpm6-gfxm
title: >-
  @angular/common: Denial of Service (DoS) via OOM in Date Formatting
  (formatDate)
summary: >-
  @angular/common: Denial of Service (DoS) via OOM in Date Formatting
  (formatDate)
severity: high
cwe:
  - CWE-400
  - CWE-1333
vendor: angular
product: '@angular/common'
ecosystem: npm
affected:
  - '@angular/common >= 22.0.0-next.0, < 22.0.1'
  - '@angular/common >= 21.0.0-next.0, < 21.2.17'
  - '@angular/common >= 20.0.0-next.0, < 20.3.25'
  - '@angular/common <= 19.2.25'
patched:
  - '@angular/common 22.0.1'
  - '@angular/common 21.2.17'
  - '@angular/common 20.3.25'
published: '2026-06-15'
updated: '2026-06-15'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-48r7-hpm6-gfxm'
references:
  - url: 'https://github.com/angular/angular/security/advisories/GHSA-48r7-hpm6-gfxm'
  - url: 'https://github.com/angular/angular/pull/69197'
  - url: >-
      https://github.com/angular/angular/commit/eeb03f4ea310e2e51ba5d53a421ec7b418e186cd
  - url: 'https://github.com/advisories/GHSA-48r7-hpm6-gfxm'
tags:
  - ghsa
  - npm
epss: 0.00583
epssPercentile: 0.45493
ingestedAt: '2026-07-07T15:41:58.906Z'
---

## Overview

A Denial of Service (DoS) vulnerability exists in the `@angular/common` package of the Angular framework. The `formatDate` function, which is also utilized by the standard Angular `DatePipe`, does not properly limit or validate the length of the `format` parameter. 

When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS).


### Impact

#### 1. Server-Side Rendering (SSR)
In Angular applications that leverage Server-Side Rendering, an attacker can supply a malicious payload with an excessively long date format string. Processing this on the server causes high CPU usage and triggers a `JavaScript heap out of memory` crash, rendering the application unavailable to all users.

#### 2. Client-Side Rendering (CSR)
In standard client-side applications, executing the vulnerable function with an excessively long format string blocks the browser's main thread, causing the browser tab to freeze and become completely unresponsive.

### Patched Versions
* 22.0.1  
* 21.2.17  
* 20.3.25

### Attack Preconditions
For this vulnerability to be exploitable, both of the following conditions must be met:
1. **Vulnerable Component Usage:** The application must format dates using the `formatDate` utility or the `DatePipe`.
2. **Attacker-Controlled Parameter:** The date format string passed to these utilities must be customizable or directly controlled by untrusted user input (e.g., parsed from query parameters, user preferences, or API responses).

*If the date format is hardcoded (e.g., `'mediumDate'`, `'shortTime'`, or static strings) or properly validated to be within a reasonable length limit, the application is not vulnerable.*

## Affected packages

- `@angular/common >= 22.0.0-next.0, < 22.0.1`
- `@angular/common >= 21.0.0-next.0, < 21.2.17`
- `@angular/common >= 20.0.0-next.0, < 20.3.25`
- `@angular/common <= 19.2.25`

## Remediation

Upgrade to a patched release:

- `@angular/common 22.0.1`
- `@angular/common 21.2.17`
- `@angular/common 20.3.25`
