CVE-2026-101895: Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
A Denial of Service (DoS) vulnerability exists in @angular/platform-server’s DOM emulation parser (domino). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as <!DOCTYPE html ), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-101895 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →