HIGH GitHub

CVE-2026-101896

Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

A denial of service (DoS) vulnerability was identified in `@angular/router` when Server-Side Rendering (SSR) is enabled on Node.js (V8). When `@angular/router` parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (`Record<string, string>`). When matrix parameter names or outlet names are numeric strings (such as `/a;990;2522`), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.

Affected Products

References

Published: 2026-09-30 · Source: GitHub · Feed updated: 2026-09-30
This high severity vulnerability was published on 2026-09-30 via GitHub. Affected: npm/@angular/router >= 22.0.0, < 22.2.0, npm/@angular/router >= 21.0.0, < 21.2.24, npm/@angular/router >= 20.0.0, < 20.3.32 and 1 more.
vulnfeed aggregates 9504 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.