CVE-2026-101896: Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
A denial of service (DoS) vulnerability was identified in @angular/router when Server-Side Rendering (SSR) is enabled on Node.js (V8).
When @angular/router parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as /a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.
Under V8’s internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like 990 followed by 2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.
Because each segment in a URL path allocates its own independent parameters object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.
References
- github.com/advisories/GHSA-ff3f-86qr-9cv3
- github.com/angular/angular/commit/03872a80bcf1c89b2b04cdd3f444b2ee954da583
- github.com/angular/angular/commit/5af61216eab8bf4a6697a1d79bda3d857c06f89d
- github.com/angular/angular/commit/ddfe21072ba32ca4cd9d7d3c6b7df66af81d58c4
- github.com/angular/angular/issues/70716
- github.com/angular/angular/pull/70717
- github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3
- nvd.nist.gov/vuln/detail/CVE-2026-101896
Code Behaviors & Features
Detect and mitigate CVE-2026-101896 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →