Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @angular/router
  4. ›
  5. CVE-2026-101896

CVE-2026-101896: Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

September 30, 2026

A denial of service (DoS) vulnerability was identified in @angular/router when Server-Side Rendering (SSR) is enabled on Node.js (V8).

When @angular/router parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as /a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.

Under V8’s internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like 990 followed by 2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.

Because each segment in a URL path allocates its own independent parameters object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.

References

  • github.com/advisories/GHSA-ff3f-86qr-9cv3
  • github.com/angular/angular/commit/03872a80bcf1c89b2b04cdd3f444b2ee954da583
  • github.com/angular/angular/commit/5af61216eab8bf4a6697a1d79bda3d857c06f89d
  • github.com/angular/angular/commit/ddfe21072ba32ca4cd9d7d3c6b7df66af81d58c4
  • github.com/angular/angular/issues/70716
  • github.com/angular/angular/pull/70717
  • github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3
  • nvd.nist.gov/vuln/detail/CVE-2026-101896

Code Behaviors & Features

Detect and mitigate CVE-2026-101896 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 19.2.25, all versions starting from 20.0.0 before 20.3.32, all versions starting from 21.0.0 before 21.2.24, all versions starting from 22.0.0 before 22.2.0

Fixed versions

  • 20.3.32
  • 21.2.24
  • 22.2.0

Solution

Upgrade to versions 20.3.32, 21.2.24, 22.2.0 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-400: Uncontrolled Resource Consumption
  • CWE-770: Allocation of Resources Without Limits or Throttling

Source file

npm/@angular/router/CVE-2026-101896.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 01 Oct 2026 00:21:12 +0000.