AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101896.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.2CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

A denial of service (DoS) vulnerability was identified in `@angular/router` when Server-Side Rendering (SSR) is enabled on Node.js (V8). When `@angular/router` parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (`Record`). When matrix parameter names or outlet names are numeric strings (such as `/a;990;2522`), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties. Under V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (`HOLEY_ELEMENTS`) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like `990` followed by `2522`) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment. Because each segment in a URL path allocates its own independent `parameters` object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately **~350x**. ### Impa

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-ff3f-86qr-9cv3

Open original source · Updated Sep 30, 2026

Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

Source severity: HIGH / 8.2

EcosystemPackageAffected rangeFirst patched
npm@angular/router>= 22.0.0, < 22.2.022.2.0
npm@angular/router>= 21.0.0, < 21.2.2421.2.24
npm@angular/router>= 20.0.0, < 20.3.3220.3.32
npm@angular/routerNot supplied

Original records & references

PUBLISHED 2026-09-30T11:40:47-04:00
MODIFIED 2026-09-30T11:40:48-04:00
INGESTED 2026-10-06T11:43:09-04:00