{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/angular-platform-server--20.0.0--20.3.31/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Angular platform-server (\u003e= 22.0.0, \u003c 22.1.6)","Angular platform-server (\u003e= 21.0.0, \u003c 21.2.23)","Angular platform-server (\u003e= 20.0.0, \u003c 20.3.31)","Angular platform-server (\u003c= 19.2.25)"],"_cs_severities":["medium"],"_cs_tags":["denial-of-service","angular","nodejs","cve-2026-101895"],"_cs_type":"advisory","_cs_vendors":["Google"],"content_html":"\u003cp\u003eA Denial of Service (DoS) vulnerability (CVE-2026-101895) exists in the @angular/platform-server library due to its reliance on the 'domino' DOM parser. When an Angular application performs server-side rendering (SSR) and processes untrusted input through template bindings like [innerHTML], the library may encounter a malformed DOCTYPE declaration ending with whitespace before the End-of-File (EOF) marker.\u003c/p\u003e\n\u003cp\u003eThe underlying issue originates in the HTML parser's tokenizer, which fails to advance the character pointer when encountering an EOF condition in the after_doctype_name_state. This triggers an infinite synchronous loop, consuming 100% of the CPU and effectively locking the single-threaded Node.js process. This vulnerability affects multiple branches of the Angular platform-server, including versions in the 19.x, 20.x, 21.x, and 22.x series. Because the loop occurs synchronously within the event loop, the application becomes unresponsive to all concurrent and subsequent requests until the process is manually restarted.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows unauthenticated remote attackers to trigger a complete Denial of Service on any Angular application utilizing SSR that binds untrusted user input to DOM-rendering properties. Success leads to an immediate hang of the Node.js server process, causing service outages for all users. The flaw is particularly critical for enterprise applications that rely on server-side rendering for SEO or performance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch immediately: Upgrade @angular/platform-server to the fixed versions (\u0026gt;= 22.1.6, \u0026gt;= 21.2.23, \u0026gt;= 20.3.31, or \u0026gt; 19.2.25).\u003c/li\u003e\n\u003cli\u003eRemediate code: Audit the codebase for instances where untrusted user input is bound directly to \u003ccode\u003e[innerHTML]\u003c/code\u003e in server-rendered templates.\u003c/li\u003e\n\u003cli\u003eImplement input validation: Use standard text interpolation \u003ccode\u003e{{ userInput }}\u003c/code\u003e or \u003ccode\u003e[textContent]\u003c/code\u003e instead of raw HTML rendering when the input source is user-controlled.\u003c/li\u003e\n\u003cli\u003eApply perimeter filtering: Implement server-side input sanitization to strip or reject input strings matching the regex \u003ccode\u003e/^\u0026lt;!DOCTYPE/i\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T22:15:03Z","date_published":"2026-09-28T22:15:03Z","id":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-dos/","summary":"A high-severity denial-of-service vulnerability in @angular/platform-server allows remote unauthenticated attackers to crash the Node.js event loop via a malformed DOCTYPE declaration.","title":"Angular SSR Denial of Service via Malformed DOCTYPE","url":"https://feed.craftedsignal.io/briefs/2026-09-angular-ssr-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Angular Platform-Server (\u003e= 20.0.0, \u003c 20.3.31)","version":"https://jsonfeed.org/version/1.1"}