Skip to content

chore(deps): update dependency @angular/router to v21.2.24 [security] - #377

Merged
davidkpiano merged 2 commits into
mainfrom
renovate/npm-angular-router-vulnerability
Oct 5, 2026
Merged

davidkpiano merged 2 commits into
mainfrom
renovate/npm-angular-router-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@angular/router (source) 21.2.8 → 21.2.24 age confidence

Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

CVE-2026-101896 / GHSA-ff3f-86qr-9cv3

More information

Details

A denial of service (DoS) vulnerability was identified in @angular/router when Server-Side Rendering (SSR) is enabled on Node.js (V8).

When @angular/router parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as /a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.

Under V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like 990 followed by 2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.

Because each segment in a URL path allocates its own independent parameters object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.

Impact

Successful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable JavaScript heap out of memory fatal error and causing a Denial of Service.

  • High Amplification: A single 11-byte segment (/a;990;2522) consumes ~20 KB–25 KB of V8 heap.
  • Low Concurrency Required:
    • With 8 KB request paths (~740 segments, within default Nginx 8 KB buffer limits), as few as 12–22 concurrent requests crash a 256 MiB–512 MiB Node.js SSR worker.
    • With smaller 1 KB–2 KB request paths (~90–180 segments), a burst of ~50–100 concurrent requests achieves the same heap exhaustion.
  • Client-side SPAs Unaffected: Pure client-side Angular applications (Single Page Applications without SSR) are not vulnerable, as local browser memory consumption does not cross a security boundary.
Attack Preconditions & Vulnerable Configurations

An application is affected only if all of the following conditions are met:

  • SSR Enabled: The application runs in a Server-Side Rendering environment powered by Node.js / V8.
  • Direct Router Parsing: User-controlled request URLs are parsed by @angular/router during SSR.
  • No Reverse-Proxy Semicolon/Segment Filtering: Upstream reverse proxies (Nginx, Cloudflare, ALB) forward URLs containing semicolons (;) and multiple path segments without stripping or rejecting them.
Exploit Payload Example

An attacker sends concurrent HTTP requests with repeated numeric matrix parameters:

GET /a;990;2522/a;990;2522/a;990;2522/... HTTP/1.1
Host: example.com

Even with paths under 2 KB, overlapping requests during SSR will rapidly consume the V8 heap until the process crashes.

Patches

The issue is resolved by updating @angular/router to enforce V8 dictionary elements storage (setUrlDerivedKey) for numeric URL-derived keys (index >= 32). This prevents V8 from allocating oversized contiguous array backing stores while preserving route matching, parameter values, and component input bindings.

  • 22.2.0
  • 21.2.24
  • 20.3.32
Workarounds & Mitigations

If you cannot immediately upgrade to a patched version, apply one of the following mitigations at your edge or reverse proxy:

  1. Block or Sanitize Matrix Parameters at the Reverse Proxy:
    Configure your reverse proxy (e.g., Nginx, Cloudflare, or AWS WAF) to reject or strip semicolons (;) in request paths before forwarding requests to the Angular SSR service:
    # Nginx example: reject requests containing matrix parameters
    if ($uri ~* ";") {
        return 400;
    }
  2. Enforce Strict Path Segment Limits:
    Reject requests with excessive path depth (e.g., more than 20–30 segments).
  3. Increase Node.js Old Space:
    Increase --max-old-space-size (e.g., to 2048 or 4096 MB) to increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

angular/angular (@​angular/router)

v21.2.24

Compare Source

router
Commit Type Description
03872a80bc fix avoid dense elements allocation for numeric URL keys

v21.2.23

Compare Source

platform-server
Commit Type Description
fc2e8fbc0b fix update domino to latest version

v21.2.22

Compare Source

platform-server
Commit Type Description
5aa6d97deb fix avoid stripping unicode whitespace during url resolution
73d8bbd27c fix update domino to latest version

v21.2.21

Compare Source

platform-browser
Commit Type Description
c19a36c2fb fix disallow event handler attributes in Meta

v21.2.20

Compare Source

core
Commit Type Description
6afe6fa781 fix sanitize host bindings on concrete hosts
http
Commit Type Description
fec5977df4 fix match header values exactly when deleting
e33d69a71c fix preserve immutability of materialized clones
caf616670f fix run root interceptors in the terminal request chain

v21.2.19

Compare Source

compiler
Commit Type Description
e2660c3dee fix disallow i18n event attributes
7b884f585a fix restrict possible event handler check to property names longer than 2 characters
http
Commit Type Description
948a8d6831 fix distinguish repeated transfer cache params
9949dccce1 fix enable xsrf for root-provided HttpClient
platform-server
Commit Type Description
f34a93c946 fix update domino to latest version

v21.2.18

Compare Source

compiler-cli
Commit Type Description
8d22cc953b fix update babel dependencies to latest v7
core
Commit Type Description
6bcce117fb fix avoid caching missing locale data
5a693bafcd fix reject dynamic script host elements
http
Commit Type Description
91df739b80 fix prevent caching of responses with Set-Cookie headers
service-worker
Commit Type Description
1804f73bec fix preserve referrer in asset requests
e86c31bf26 fix preserve referrer policy in asset requests

v21.2.17

Compare Source

Deprecations

platform-server
  • XHR support in @angular/platform-server is deprecated. Use standard fetch APIs instead.
common
Commit Type Description
86a56dc279 fix Limits date format string length
d846326b07 fix skip transfer cache for uncacheable HTTP traffic
bc55749698 fix use cryptographically secure SHA-256 for transfer cache key generation
compiler
Commit Type Description
dc9c99636d fix sanitize two-way properties
core
Commit Type Description
1523061137 fix harden TransferState restoration against DOM clobbering
88832c84f8 fix validate lowercase SVG animation attribute names (#​69269)
http
Commit Type Description
bcb1b7ea25 fix preserve empty referrer option in HttpRequest
a810a319d1 fix Rejects non-HTTP(S) URLs in JSONP requests
e245d40c4d fix skip transfer cache for fetch credentialed requests
platform-server
Commit Type Description
35510746b7 fix harden platform location origin validation during SSR
13fb0afe93 refactor deprecate ServerXhr (#​69255)
service-worker
Commit Type Description
b9d29381bb fix Strips sensitive headers on cross-origin redirects

v21.2.16

Compare Source

common
Commit Type Description
f6d8e642b0 fix only strip a literal /index.html suffix from URLs
compiler
Commit Type Description
ae1c8a1f7a fix move projection attributes into constants
core
Commit Type Description
3fd6897a67 fix harden inherit definition feature against polluted prototypes
7e38336dc7 fix use Object.create(null) for LOCALE_DATA as a hardening measure
platform-server
Commit Type Description
66821c4ed5 fix throw on suspicious URLs and restrict protocol-relative URLs
d3170031b6 fix update domino to latest version

v21.2.15

Compare Source

common
Commit Type Description
7f4ac78994 fix add upper bounds for digitsInfo
300f61feb3 fix sanitize placeholder
compiler
Commit Type Description
0b07f47bd6 fix normalize tag names with custom namespaces in DomElementSchemaRegistry (#​68925)
eb1cbbf2eb fix prevent namespaced SVG <style> elements from being stripped
cc1378d54b fix sanitize dynamic href and xlink:href bindings on SVG a elements (#​68925)
782e01594e fix strip namespaced SVG script elements during template compilation (#​68925)
core
Commit Type Description
ff12fe55ac fix normalize tag names in runtime i18n attribute security context lookup (#​68925)
e6fe77cc97 fix sanitize meta selectors
daaf32937f fix support prefix-insensitive DOM schema lookups and compile-time i18n attribute validation (#​68925)
dada86e43d fix synchronize core sanitization schema with compiler (#​68925)
http
Commit Type Description
582a417bd2 fix exclude withCredentials requests from transfer cache
5c6d6df34b fix skip TransferCache for cookie-bearing requests by default
platform-server
Commit Type Description
37e8aadf87 fix prevent SSRF bypasses via backslash URLs in HttpClient
72696e244e fix secure location and document initialization against SSRF and path hijack
service-worker
Commit Type Description
b8bd49341d fix Preserves explicit 'credentials: omit' in asset requests
ca32fc1000 fix Preserves HTTP cache mode in asset group requests

v21.2.14

Compare Source

compiler
Commit Type Description
68282dff9f fix strip namespaced SVG script elements during template compilation
core
Commit Type Description
c0f52272ed fix do not insert todo when migrating void @​Output
938a7f3edd fix makes resource URL sanitizer lookup case-insensitive
0fb2724194 fix reject script element as a dynamic component host
49113ac0ef fix visit ICU expressions in signal migration schematics
router
Commit Type Description
099bf577ee fix skip scroll-to-top on initial navigation when hydrating

v21.2.13

Compare Source

core
Commit Type Description
1c6553e97d fix disallow event attribute bindings in host bindings unconditionally
platform-server
Commit Type Description
629905d537 fix add allowedHosts option to renderModule and renderApplication
0b7192f441 fix forward BEFORE_APP_SERIALIZED errors to ErrorHandler

v21.2.12

Compare Source

core
Commit Type Description
fe13bb669d fix allow explicit read generic with signal input transforms
3430251fef fix i18n flags leaking on errors
1aeebbe304 fix respect ngSkipHydration on components with projectable nodes in LContainers
9e38ed7d57 fix sanitizer typings
7a05a9a71a fix validate security-sensitive attributes in i18n bindings
c37f6ca42f fix visit ng-let expression value in signal migration schematics
forms
Commit Type Description
03ad53863b fix prohibit concurrent submits in signal forms

v21.2.11

Compare Source

common
Commit Type Description
10ad3c0692 fix prevent focus from scrollToAnchor
compiler
Commit Type Description
4f5d8a2c0b fix let declaration span not including end character
core
Commit Type Description
a40e2cebc8 fix fix ordering of view queries metadata in JIT mode
885a1a1d97 fix guard against non-object events and avoid listener wrapper identity mismatch
7a64aff9b5 fix prevent event replay double-invocation when element hydrates before app stability
platform-server
Commit Type Description
be1f80a253 fix ensure origin has a trailing slash when parsing url

v21.2.10

Compare Source

docs
Commit Type Description
0d5ee9ae1b fix link formatting in "Animating your Application with CSS"
migrations
Commit Type Description
5533ab4f56 fix fix NgClass leaving trailing comma after removal
router
Commit Type Description
580212c995 fix restore internal URL on popstate when browserUrl is used

v21.2.9

Compare Source

core
Commit Type Description
f603d4714f fix escape forward slashes in transfer state to prevent crawler indexing
http
Commit Type Description
540536c386 fix add CSP nonce support to JsonpClientBackend
63a857b874 fix Don't on Passthru outside of reactive context
platform-server
Commit Type Description
e0b5078cf2 fix prevent SSRF bypasses via protocol-relative and backslash URLs
router
Commit Type Description
684e9fd53d fix normalize multiple leading slashes in URL parser

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 4, 2026
@renovate

renovate Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: pnpm-lock.yaml

<--- Last few GCs --->

[1323:0x114c0000]   114520 ms: Scavenge 1485.6 (1497.0) -> 1478.7 (1496.8) MB, pooled: 0 MB, 5.94 / 0.00 ms  (average mu = 0.293, current mu = 0.264) allocation failure; 
[1323:0x114c0000]   116077 ms: Mark-Compact (reduce) 1484.3 (1497.3) -> 1474.5 (1479.2) MB, pooled: 0 MB, 101.61 / 0.00 ms  (+ 1378.1 ms in 82 steps since start of marking, biggest step 23.7 ms, walltime since start of marking 1556 ms) (average mu = 0.302
FATAL ERROR: Ineffective mark-compacts near heap limit Allocation failed - JavaScript heap out of memory
----- Native stack trace -----

 1: 0xf49c57 node::OOMErrorHandler(char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/24.8.0/bin/node]
 2: 0x13a6050 v8::Utils::ReportOOMFailure(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/24.8.0/bin/node]
 3: 0x13a613f v8::internal::V8::FatalProcessOutOfMemory(v8::internal::Isolate*, char const*, v8::OOMDetails const&) [/opt/containerbase/tools/node/24.8.0/bin/node]
 4: 0x163ec25  [/opt/containerbase/tools/node/24.8.0/bin/node]
 5: 0x163ec52  [/opt/containerbase/tools/node/24.8.0/bin/node]
 6: 0x163ef4a v8::internal::Heap::RecomputeLimits(v8::internal::GarbageCollector, v8::base::TimeTicks) [/opt/containerbase/tools/node/24.8.0/bin/node]
 7: 0x164f46a  [/opt/containerbase/tools/node/24.8.0/bin/node]
 8: 0x1653810  [/opt/containerbase/tools/node/24.8.0/bin/node]
 9: 0x20e6641  [/opt/containerbase/tools/node/24.8.0/bin/node]
/usr/local/bin/node: line 18:  1323 Aborted                 /opt/containerbase/tools/node/24.8.0/bin/node "$@"

@changeset-bot

changeset-bot Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: bae2149

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: a517c534-b319-4638-a956-eaae9d029f51

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@nx-cloud

nx-cloud Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit bae2149

Command Status Duration Result
nx affected --targets=test:sherif,test:knip,tes... ✅ Succeeded 1m 30s View ↗
nx run-many --target=build --exclude=examples/** ✅ Succeeded <1s View ↗

☁️ Nx Cloud last updated this comment at 2026-10-04 22:03:24 UTC

@pkg-pr-new

pkg-pr-new Bot commented Oct 4, 2026

Copy link
Copy Markdown
@tanstack/angular-store

npm i https://pkg.pr.new/@tanstack/angular-store@377

@tanstack/lit-store

npm i https://pkg.pr.new/@tanstack/lit-store@377

@tanstack/octane-store

npm i https://pkg.pr.new/@tanstack/octane-store@377

@tanstack/preact-store

npm i https://pkg.pr.new/@tanstack/preact-store@377

@tanstack/react-store

npm i https://pkg.pr.new/@tanstack/react-store@377

@tanstack/solid-store

npm i https://pkg.pr.new/@tanstack/solid-store@377

@tanstack/store

npm i https://pkg.pr.new/@tanstack/store@377

@tanstack/svelte-store

npm i https://pkg.pr.new/@tanstack/svelte-store@377

@tanstack/vue-store

npm i https://pkg.pr.new/@tanstack/vue-store@377

commit: bae2149

@renovate

renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@davidkpiano
davidkpiano merged commit c1a40d4 into main Oct 5, 2026
9 checks passed
@davidkpiano
davidkpiano deleted the renovate/npm-angular-router-vulnerability branch October 5, 2026 11:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant