Repository navigation
chore(deps): update dependency @angular/router to v21.2.24 [security] - autoclosed - #385
renovate[bot] wants to merge 1 commit into
Conversation
|
|
View your CI Pipeline Execution ↗ for commit daee51d
☁️ Nx Cloud last updated this comment at |
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
@tanstack/angular-store
@tanstack/lit-store
@tanstack/octane-store
@tanstack/preact-store
@tanstack/react-store
@tanstack/solid-store
@tanstack/store
@tanstack/svelte-store
@tanstack/vue-store
commit: |
This PR contains the following updates:
21.2.8→21.2.24Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
CVE-2026-101896 / GHSA-ff3f-86qr-9cv3
More information
Details
A denial of service (DoS) vulnerability was identified in
@angular/routerwhen Server-Side Rendering (SSR) is enabled on Node.js (V8).When
@angular/routerparses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as/a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.Under V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (
HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like990followed by2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.Because each segment in a URL path allocates its own independent
parametersobject, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.Impact
Successful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable
JavaScript heap out of memoryfatal error and causing a Denial of Service./a;990;2522) consumes ~20 KB–25 KB of V8 heap.Attack Preconditions & Vulnerable Configurations
An application is affected only if all of the following conditions are met:
@angular/routerduring SSR.;) and multiple path segments without stripping or rejecting them.Exploit Payload Example
An attacker sends concurrent HTTP requests with repeated numeric matrix parameters:
Even with paths under 2 KB, overlapping requests during SSR will rapidly consume the V8 heap until the process crashes.
Patches
The issue is resolved by updating
@angular/routerto enforce V8 dictionary elements storage (setUrlDerivedKey) for numeric URL-derived keys (index >= 32). This prevents V8 from allocating oversized contiguous array backing stores while preserving route matching, parameter values, and component input bindings.22.2.021.2.2420.3.32Workarounds & Mitigations
If you cannot immediately upgrade to a patched version, apply one of the following mitigations at your edge or reverse proxy:
Configure your reverse proxy (e.g., Nginx, Cloudflare, or AWS WAF) to reject or strip semicolons (
;) in request paths before forwarding requests to the Angular SSR service:Reject requests with excessive path depth (e.g., more than 20–30 segments).
Increase
--max-old-space-size(e.g., to 2048 or 4096 MB) to increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
angular/angular (@angular/router)
v21.2.24Compare Source
router
v21.2.23Compare Source
platform-server
v21.2.22Compare Source
platform-server
v21.2.21Compare Source
platform-browser
v21.2.20Compare Source
core
http
v21.2.19Compare Source
compiler
http
platform-server
v21.2.18Compare Source
compiler-cli
core
http
service-worker
v21.2.17Compare Source
Deprecations
platform-server
@angular/platform-serveris deprecated. Use standardfetchAPIs instead.common
compiler
core
http
platform-server
service-worker
v21.2.16Compare Source
common
compiler
core
platform-server
v21.2.15Compare Source
common
compiler
core
http
platform-server
service-worker
v21.2.14Compare Source
compiler
core
router
v21.2.13Compare Source
core
platform-server
allowedHostsoption torenderModuleandrenderApplicationv21.2.12Compare Source
core
forms
v21.2.11Compare Source
common
compiler
core
platform-server
v21.2.10Compare Source
docs
migrations
router
browserUrlis usedv21.2.9Compare Source
core
http
platform-server
router
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled because a matching PR was automerged previously.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.