Disclosure summary
A denial of service (DoS) vulnerability was identified in `@angular/router` when Server-Side Rendering (SSR) is enabled on Node.js (V8). When `@angular/router` parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (`Record`). When matrix parameter names or outlet names are numeric strings (such as `/a;990;2522`), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties. Under V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (`HOLEY_ELEMENTS`) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like `990` followed by `2522`) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment. Because each segment in a URL path allocates its own independent `parameters` object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately **~350x**. ### Impa
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-ff3f-86qr-9cv3
Open original source · Updated Sep 30, 2026
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
Source severity: HIGH / 8.2
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | @angular/router | >= 22.0.0, < 22.2.0 | 22.2.0 |
| npm | @angular/router | >= 21.0.0, < 21.2.24 | 21.2.24 |
| npm | @angular/router | >= 20.0.0, < 20.3.32 | 20.3.32 |
| npm | @angular/router | Not supplied |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T11:40:47-04:00
MODIFIED 2026-09-30T11:40:48-04:00
INGESTED 2026-10-06T11:43:09-04:00