HIGH GitHub
CVE-2026-101895
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
A Denial of Service (DoS) vulnerability exists in `@angular/platform-server`'s DOM emulation parser (`domino`). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as `<!DOCTYPE html `), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process.
### Technical Description
In Angular Server-Side Rendering (SSR), `@angular/platform-server` uses `domino
Affected Products
- npm/@angular/platform-server >= 22.0.0, < 22.1.6
- npm/@angular/platform-server >= 21.0.0, < 21.2.23
- npm/@angular/platform-server >= 20.0.0, < 20.3.31
- npm/@angular/platform-server <= 19.2.25
References
- https://github.com/advisories/GHSA-f67j-2jqw-jpq7
- https://github.com/angular/angular/security/advisories/GHSA-f67j-2jqw-jpq7
- https://github.com/advisories/GHSA-f67j-2jqw-jpq7
This high severity vulnerability was published on 2026-09-28 via GitHub. Affected: npm/@angular/platform-server >= 22.0.0, < 22.1.6, npm/@angular/platform-server >= 21.0.0, < 21.2.23, npm/@angular/platform-server >= 20.0.0, < 20.3.31 and 1 more.
vulnfeed aggregates 13624 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.