HIGH GitHub

CVE-2026-101895

Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE

A Denial of Service (DoS) vulnerability exists in `@angular/platform-server`'s DOM emulation parser (`domino`). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as `<!DOCTYPE html `), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process. ### Technical Description In Angular Server-Side Rendering (SSR), `@angular/platform-server` uses `domino

Affected Products

References

Published: 2026-09-28 · Source: GitHub · Feed updated: 2026-09-29
This high severity vulnerability was published on 2026-09-28 via GitHub. Affected: npm/@angular/platform-server >= 22.0.0, < 22.1.6, npm/@angular/platform-server >= 21.0.0, < 21.2.23, npm/@angular/platform-server >= 20.0.0, < 20.3.31 and 1 more.
vulnfeed aggregates 13624 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.