<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Angular/Router (&gt;= 20.0.0, &lt; 20.3.32) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@angular/router--20.0.0--20.3.32/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 16:26:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@angular/router--20.0.0--20.3.32/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service in Angular Router via Numeric URL Matrix Parameters</title><link>https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-dos/</link><pubDate>Wed, 30 Sep 2026 16:26:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-dos/</guid><description>A high-severity denial of service vulnerability in @angular/router enables memory exhaustion in Node.js SSR environments through crafted URLs with numeric matrix parameters that trigger oversized V8 object allocation.</description><content:encoded><![CDATA[<p>A memory-exhaustion vulnerability (CVE-2026-101896) exists in <code>@angular/router</code> when Server-Side Rendering (SSR) is utilized within a Node.js/V8 environment. The vulnerability arises from how the router parses URL segments and matrix parameters into JavaScript objects. When these parameters contain numeric strings, the V8 engine interprets them as array indices rather than object keys. Due to V8's internal property-storage heuristics, these numeric keys cause the allocation of dense array backing stores instead of sparse dictionary storage.</p>
<p>By crafting URLs with repeated numeric matrix parameters (e.g., <code>/a;990;2522</code>), an attacker achieves a memory amplification factor of approximately 350x. This allows an unauthenticated remote attacker to trigger a fatal <code>JavaScript heap out of memory</code> error in the SSR worker with relatively low concurrency. This vulnerability is specific to SSR implementations and does not affect pure client-side Single Page Applications (SPAs).</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a target application utilizing Angular SSR with Node.js.</li>
<li>Attacker probes the endpoint to confirm the handling of URL matrix parameters (semicolons in path segments).</li>
<li>Attacker crafts a long request path containing multiple segments, each featuring repeated numeric matrix parameters (e.g., <code>;990;2522</code>).</li>
<li>Attacker sends multiple concurrent HTTP requests to the SSR endpoint, utilizing standard web-server buffer capacities (e.g., 2 KB to 8 KB path lengths).</li>
<li>The <code>@angular/router</code> component parses the URL, populating a <code>parameters</code> object with the malicious numeric keys.</li>
<li>V8 engine interprets these keys as dense array indices and allocates large, contiguous <code>HOLEY_ELEMENTS</code> backing stores for each segment.</li>
<li>Heap memory consumption spikes rapidly due to the 350x memory amplification.</li>
<li>Node.js process reaches the configured heap limit, triggering a process crash and resulting in a Denial of Service.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the termination of the SSR worker process, causing a service outage for users relying on server-side rendered content. An attacker can force this state with as few as 12 to 22 concurrent requests if the path length is near 8 KB, or 50 to 100 requests for smaller paths, effectively rendering the application unavailable.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for detection and remediation:</p>
<ul>
<li>Upgrade <code>@angular/router</code> to version 22.2.0, 21.2.24, 20.3.32, or later to address CVE-2026-101896.</li>
<li>Configure upstream reverse proxies (Nginx, WAF) to block or strip semicolons (<code>;</code>) from incoming request URIs to prevent malicious parameters from reaching the Angular router.</li>
<li>Implement strict request path segment limits at the edge to reduce the maximum possible heap allocation per request.</li>
<li>Monitor SSR worker process memory usage via monitoring tools; sudden spikes in heap memory accompanied by high frequencies of semicolon-containing URLs indicate potential exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>angular</category><category>nodejs</category><category>v8</category><category>cve-2026-101896</category></item></channel></rss>