{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@angular/router--21.0.0--21.2.24/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:google:angular:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@angular/router (\u003e= 22.0.0, \u003c 22.2.0)","@angular/router (\u003e= 21.0.0, \u003c 21.2.24)","@angular/router (\u003e= 20.0.0, \u003c 20.3.32)","@angular/router (\u003c= 19.2.25)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","angular","nodejs","v8","cve-2026-101896"],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eA memory-exhaustion vulnerability (CVE-2026-101896) exists in \u003ccode\u003e@angular/router\u003c/code\u003e when Server-Side Rendering (SSR) is utilized within a Node.js/V8 environment. The vulnerability arises from how the router parses URL segments and matrix parameters into JavaScript objects. When these parameters contain numeric strings, the V8 engine interprets them as array indices rather than object keys. Due to V8's internal property-storage heuristics, these numeric keys cause the allocation of dense array backing stores instead of sparse dictionary storage.\u003c/p\u003e\n\u003cp\u003eBy crafting URLs with repeated numeric matrix parameters (e.g., \u003ccode\u003e/a;990;2522\u003c/code\u003e), an attacker achieves a memory amplification factor of approximately 350x. This allows an unauthenticated remote attacker to trigger a fatal \u003ccode\u003eJavaScript heap out of memory\u003c/code\u003e error in the SSR worker with relatively low concurrency. This vulnerability is specific to SSR implementations and does not affect pure client-side Single Page Applications (SPAs).\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target application utilizing Angular SSR with Node.js.\u003c/li\u003e\n\u003cli\u003eAttacker probes the endpoint to confirm the handling of URL matrix parameters (semicolons in path segments).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a long request path containing multiple segments, each featuring repeated numeric matrix parameters (e.g., \u003ccode\u003e;990;2522\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eAttacker sends multiple concurrent HTTP requests to the SSR endpoint, utilizing standard web-server buffer capacities (e.g., 2 KB to 8 KB path lengths).\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003e@angular/router\u003c/code\u003e component parses the URL, populating a \u003ccode\u003eparameters\u003c/code\u003e object with the malicious numeric keys.\u003c/li\u003e\n\u003cli\u003eV8 engine interprets these keys as dense array indices and allocates large, contiguous \u003ccode\u003eHOLEY_ELEMENTS\u003c/code\u003e backing stores for each segment.\u003c/li\u003e\n\u003cli\u003eHeap memory consumption spikes rapidly due to the 350x memory amplification.\u003c/li\u003e\n\u003cli\u003eNode.js process reaches the configured heap limit, triggering a process crash and resulting in a Denial of Service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the termination of the SSR worker process, causing a service outage for users relying on server-side rendered content. An attacker can force this state with as few as 12 to 22 concurrent requests if the path length is near 8 KB, or 50 to 100 requests for smaller paths, effectively rendering the application unavailable.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and remediation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@angular/router\u003c/code\u003e to version 22.2.0, 21.2.24, 20.3.32, or later to address CVE-2026-101896.\u003c/li\u003e\n\u003cli\u003eConfigure upstream reverse proxies (Nginx, WAF) to block or strip semicolons (\u003ccode\u003e;\u003c/code\u003e) from incoming request URIs to prevent malicious parameters from reaching the Angular router.\u003c/li\u003e\n\u003cli\u003eImplement strict request path segment limits at the edge to reduce the maximum possible heap allocation per request.\u003c/li\u003e\n\u003cli\u003eMonitor SSR worker process memory usage via monitoring tools; sudden spikes in heap memory accompanied by high frequencies of semicolon-containing URLs indicate potential exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T16:26:49Z","date_published":"2026-09-30T16:26:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-dos/","summary":"A high-severity denial of service vulnerability in @angular/router enables memory exhaustion in Node.js SSR environments through crafted URLs with numeric matrix parameters that trigger oversized V8 object allocation.","title":"Denial of Service in Angular Router via Numeric URL Matrix Parameters","url":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - @Angular/Router (\u003e= 21.0.0, \u003c 21.2.24)","version":"https://jsonfeed.org/version/1.1"}