PT-2026-103484 · Google+1 · @Angular/Router+1

CVE-2026-101896

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @angular/router versions prior to 20.3.32 @angular/router versions prior to 21.2.24 @angular/router versions prior to 22.2.0
Description A denial of service (DoS) issue exists in @angular/router when Server-Side Rendering (SSR) is enabled on Node.js. The problem occurs when the router parses incoming request URLs and extracts path segments, matrix parameters, and child outlets into JavaScript objects. If matrix parameter names or outlet names are numeric strings, the V8 JavaScript engine interprets them as array-indexed properties. This causes V8 to allocate a dense array backing store (HOLEY ELEMENTS) sized to the maximum index instead of using sparse dictionary storage, leading to significant memory amplification. An unauthenticated remote attacker can exploit this by sending requests with repeated numeric matrix parameters to exhaust the Node.js old-space heap, resulting in a JavaScript heap out of memory fatal error that crashes the SSR worker.
Recommendations Update @angular/router to version 20.3.32 or later. Update @angular/router to version 21.2.24 or later. Update @angular/router to version 22.2.0 or later. Configure reverse proxies to reject or strip semicolons (;) in request paths before they reach the SSR service. Restrict requests with excessive path depth, such as those exceeding 20 to 30 segments. Increase the --max-old-space-size configuration in Node.js to raise the memory threshold.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101896
GHSA-FF3F-86QR-9CV3

Affected Products

@Angular/Router
Node.Js