HIGH GitHub
CVE-2026-101896
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
A denial of service (DoS) vulnerability was identified in `@angular/router` when Server-Side Rendering (SSR) is enabled on Node.js (V8).
When `@angular/router` parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (`Record<string, string>`). When matrix parameter names or outlet names are numeric strings (such as `/a;990;2522`), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.
Affected Products
- npm/@angular/router >= 22.0.0, < 22.2.0
- npm/@angular/router >= 21.0.0, < 21.2.24
- npm/@angular/router >= 20.0.0, < 20.3.32
- npm/@angular/router <= 19.2.25
References
- https://github.com/advisories/GHSA-ff3f-86qr-9cv3
- https://github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3
- https://github.com/angular/angular/issues/70716
- https://github.com/angular/angular/pull/70717
This high severity vulnerability was published on 2026-09-30 via GitHub. Affected: npm/@angular/router >= 22.0.0, < 22.2.0, npm/@angular/router >= 21.0.0, < 21.2.24, npm/@angular/router >= 20.0.0, < 20.3.32 and 1 more.
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.